#VU70715 Use of uninitialized resource in LibTIFF - CVE-2022-34266
Published: January 5, 2023
LibTIFF
LibTIFF
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to an invalid range may be passed as an argument to the memset() function within TIFFFetchStripThing() in tif_dirread.c when processing a malicious TIFF file. A remote attacker can trick the victim into opening a specially crafted TIFF file, trigger uninitialized usage of resources and perform a denial of service attack.