PT-2022-6895 · Libtiff+8 · Libtiff+8

CVE-2022-2520

·

Published

2022-05-22

·

Updated

2025-06-03

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libtiff version 4.4.0rc1
Description A flaw in the rotateImage() function in the tiffcrop.c file at line 8621 can cause a program crash when reading a crafted input due to a sysmalloc assertion failure. This issue is related to an incorrect buffer size calculation, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For libtiff version 4.4.0rc1, consider disabling the rotateImage() function as a temporary workaround until a patch is available to prevent potential crashes when reading crafted inputs.

Exploit

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:0095
ALSA-2023:0302
ALT-PU-2022-3360
ALT-PU-2022-3428
ALT-PU-2025-7532
BDU:2023-05419
CESA-2023_0095
CVE-2022-2520
DSA-5333-1
MGASA-2022-0410
OESA-2022-1935
OPENSUSE-SU-2022_3690-1
OPENSUSE-SU-2024:12420-1
RHSA-2023:0095
RHSA-2023:0302
RHSA-2023_0095
RHSA-2023_0302
RLSA-2023:0095
RLSA-2023:0302
SUSE-SU-2022:3679-1
SUSE-SU-2022:3690-1
USN-5714-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Libtiff