UBUNTU-CVE-2022-0908
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-0908
UBUNTU-CVE-2022-0908
Summary:
Details: Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
References: https://ubuntu.com/security/CVE-2022-0908, https://gitlab.com/libtiff/libtiff/-/commit/a95b799f65064e4ba2e2dfc206808f86faf93e85, https://gitlab.com/libtiff/libtiff/-/issues/383, https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0908.json, https://ubuntu.com/security/notices/USN-5523-1, https://ubuntu.com/security/notices/USN-5523-2, https://www.cve.org/CVERecord?id=CVE-2022-0908
Affected packages
Package
Name: tiff
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
