Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2520


A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.


Published

2022-08-31T16:15:11.117

Last Modified

2024-11-21T07:01:09.950

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-131
  • Type: Secondary
    CWE-617

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application libtiff libtiff 4.4.0 Yes
Operating System debian debian_linux 11.0 Yes

References