Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia: 2022-0337 Moderate: tiffcrop Out Of Bounds Exploit

mageia
Calendar Grey September 16, 2022
Dist Mageia Esm H88
Mageia patches libjpeg to address severe vulnerability permitting possible crashes and security breaches. More information can be found in the advisory.
libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write

Summary

libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation. (CVE-2022-2867)
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop. (CVE-2022-2868)
libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation. (CVE-2022-2869)

References

- https://bugs.mageia.org/show_bug.cgi?id=30836

-

- https://www.cve.org/CVERecord?id=CVE-2022-2867

- https://www.cve.org/CVERecord?id=CVE-2022-2868

- https://www.cve.org/CVERecord?id=CVE-2022-2869

Resolution

SRPMS

- 8/core/libtiff-4.2.0-1.8.mga8

Publication date: 16 Sep 2022
URL: https://advisories.mageia.org/MGASA-2022-0337.html
Type: security
CVE: CVE-2022-2867, CVE-2022-2868, CVE-2022-2869

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here