Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2022-0891

Published: August 31, 2023Last modified: August 31, 2023

Description

A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

Severity score breakdown

ParameterValue
Base score7.1
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTStiffNot affected (4.4.0-r4)
StreamtiffNot affected (4.5.1-r0)

References

ON THIS PAGE