Show filters
266 Total Results
Displaying 51-60 of 266
Sort by:
Attacker Value
Unknown
CVE-2022-2520
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.
0
Attacker Value
Unknown
CVE-2022-2519
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1
0
Attacker Value
Unknown
CVE-2022-1354
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
0
Attacker Value
Unknown
CVE-2022-1355
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
0
Attacker Value
Unknown
CVE-2022-2953
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.
0
Attacker Value
Unknown
CVE-2022-2869
Disclosure Date: August 17, 2022 (last updated February 24, 2025)
libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation.
0
Attacker Value
Unknown
CVE-2022-2868
Disclosure Date: August 17, 2022 (last updated February 24, 2025)
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
0
Attacker Value
Unknown
CVE-2022-2867
Disclosure Date: August 17, 2022 (last updated February 24, 2025)
libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation.
0
Attacker Value
Unknown
CVE-2022-34526
Disclosure Date: July 29, 2022 (last updated February 24, 2025)
A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.
0
Attacker Value
Unknown
CVE-2022-34266
Disclosure Date: July 19, 2022 (last updated February 24, 2025)
The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the memset() function within TIFFFetchStripThing() in tif_dirread.c. This will cause TIFFFetchStripThing() to segfault after use of an uninitialized resource.
0