Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34266


The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the memset() function within TIFFFetchStripThing() in tif_dirread.c. This will cause TIFFFetchStripThing() to segfault after use of an uninitialized resource.


Published

2022-07-19T20:15:11.367

Last Modified

2024-11-21T07:09:10.923

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-908

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application libtiff libtiff 4.0.3-35 Yes
Operating System amazon linux_2 - No

References