Vulnerability CVE-2022-3970: Information

Description

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Nov. 13, 2022
Modified: Nov. 17, 2023
Error type identifier: CWE-189

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libtiffsisyphus4.4.0-alt24.4.0-alt4ALT-PU-2022-3360-1311934Fixed
libtiffsisyphus_e2k4.4.0-alt24.4.0-alt4ALT-PU-2022-7474-1-Fixed
libtiffsisyphus_riscv644.4.0-alt24.4.0-alt4ALT-PU-2022-7483-1-Fixed
libtiffp104.4.0-alt24.4.0-alt2ALT-PU-2022-3428-1311968Fixed
libtiffp10_e2k4.4.0-alt24.4.0-alt2ALT-PU-2022-7593-1-Fixed
libtiffc10f14.4.0-alt24.4.0-alt2ALT-PU-2022-3428-1311968Fixed
libtiffp114.4.0-alt24.4.0-alt4ALT-PU-2022-3360-1311934Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
N/A
  • Exploit
  • Issue Tracking
  • Third Party Advisory
N/A
  • Patch
N/A
  • Third Party Advisory
  • VDB Entry
N/A
  • Product
https://security.netapp.com/advisory/ntap-20221215-0009/
  • Third Party Advisory
[debian-lts-announce] 20230120 [SECURITY] [DLA 3278-1] tiff security update
  • Mailing List
  • Third Party Advisory
https://support.apple.com/kb/HT213843
  • Release Notes
  • Third Party Advisory
https://support.apple.com/kb/HT213841
  • Release Notes
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*
      End excliding
      4.5.0

      Configuration 2

      cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
      End excliding
      16.5.1

      cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
      End excliding
      16.6

      cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
      End excliding
      16.6

      cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
      End excliding
      13.5