Bugzilla – Bug 1199483
VUL-0: CVE-2022-1622: tiff: out-of-bounds read in LZWDecode
Last modified: 2022-05-12 14:16:49 UTC
CVE-2022-1622 LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1622 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1622 https://gitlab.com/libtiff/libtiff/-/commit/b4e79bfa0c7d2d08f6f1e7ec38143fc8cb11394a https://gitlab.com/libtiff/libtiff/-/issues/410 https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1622.json
Not Affected: - SUSE:SLE-11:Update/tiff 3.8.2 - SUSE:SLE-12:Update/tiff 4.0.9 - SUSE:SLE-15:Update/tiff 4.0.9 - openSUSE:Factory/tiff 4.3.0
Closing