ZeroHour

CVE-2022-1623

PoC
CVSS 3.1
5.5 medium
EPSS
1%p68
Published
()
Modified
Description

LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.

Vendors
libtifffedoraprojectnetappdebian
Products
libtiff, fedora, ontap select deploy administration utility, debian linux
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.