MEDIUM 5.5 Microsoft
CVE-2022-3570
Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash potential information disclosure or any other context-dependent impact
Microsoft Security Update 2022-Oct: Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash potential information disclosure or any other context-dependent impact
Affected Products
- cm1 libtiff 4.4.0-4 on CBL Mariner 1.0
- cbl2 libtiff 4.4.0-5 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-3570
- https://nvd.nist.gov/vuln/detail/CVE-2022-3570
This medium severity vulnerability with a CVSS score of 5.5 was published on 2022-10-11 via Microsoft. Affected: cm1 libtiff 4.4.0-4 on CBL Mariner 1.0, cbl2 libtiff 4.4.0-5 on CBL Mariner 2.0.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.