PT-2022-5611 · Libtiff+10 · Libtiff+10
CVE-2022-3970
·
Published
2022-11-08
·
Updated
2025-09-24
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LibTIFF (affected versions not specified)
Description
A critical issue was found in LibTIFF, affecting the
TIFFReadRGBATileExt function in the libtiff/tif getimage.c file. This issue is related to an integer overflow and can be exploited remotely using a specially crafted file, potentially leading to a denial of service. The exploit has been disclosed publicly.Recommendations
To fix this issue, it is recommended to apply a patch. The patch with the name
227500897dfb07fb7d27f7aa570050e62617e3be is available to address this issue. As a temporary workaround, consider disabling the TIFFReadRGBATileExt function until a patch is applied. Additionally, improved memory handling can help mitigate the issue.Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Libtiff
Linuxmint
Apple Macos
Red Hat
Red Os
Suse
Ubuntu