Out-of-bounds read in LibTIFF - CVE-2022-4645

 

Out-of-bounds read in LibTIFF - CVE-2022-4645

Published: March 22, 2023


Vulnerability identifier: #VU73915
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-4645
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within tools/tiffcp.c. A remote attacker can pass a specially crafted TIFF file to the application using the affected library, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.


Affected software

LibTIFF
Amazon Linux AMI
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Fedora
Data Lakehouse
Migration Toolkit for Runtimes
tkimg
libtiff (Red Hat package)
libtiff
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2022-4645

Install updates from vendor's website.

LibTIFF - update to 4.5.0
Data Lakehouse - update to 1.1.0.0
Migration Toolkit for Runtimes - update to 1.2.6
tkimg - addressed in versions 1.4.14-3.fc36, 1.4.14-3.fc37, 1.4.14-3.fc38
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
libtiff (Red Hat package) - addressed in versions 4.0.9-31.el8, 4.4.0-7.el9
libtiff - update to 4.4.0-4
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins