Out-of-Bounds Read Vulnerability in LibTIFF 4.4.0 Affects Denial of Service
CVE-2022-4645
5.5MEDIUM
What is CVE-2022-4645?
LibTIFF version 4.4.0 is vulnerable to an out-of-bounds read error located in the 'tiffcp' tool, specifically in the source file tools/tiffcp.c at line 948. This vulnerability allows attackers to execute a denial-of-service attack by providing a specially crafted TIFF file, which can disrupt service and render applications utilizing LibTIFF unresponsive. Users who compile LibTIFF from source code can apply the necessary fix by incorporating commit e8131125.
Affected Version(s)
libtiff <=4.4.0