Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2022.0410
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2022-0410)
Summary:The remote host is missing an update for the 'libtiff' package(s) announced via the MGASA-2022-0410 advisory.
Description:Summary:
The remote host is missing an update for the 'libtiff' package(s) announced via the MGASA-2022-0410 advisory.

Vulnerability Insight:
There is a double free or corruption in rotateImage() at tiffcrop.c:8839
found in libtiff 4.4.0rc1. (CVE-2022-2519)

A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail
in rotateImage() at tiffcrop.c:8621 that can cause program crash when
reading a crafted input. (CVE-2022-2520)

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free
operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that
can cause a program crash and denial of service while processing crafted
input. (CVE-2022-2521)

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library
Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory
access via crafted TIFF image file which could result into application
crash, potential information disclosure or any other context-dependent
impact. (CVE-2022-3570)

LibTIFF 4.4.0 has an out-of-bounds write in
extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing
attackers to cause a denial-of-service via a crafted tiff file.
(CVE-2022-3598)

Affected Software/OS:
'libtiff' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-2519
DSA-5333
https://www.debian.org/security/2023/dsa-5333
https://gitlab.com/libtiff/libtiff/-/issues/423
https://gitlab.com/libtiff/libtiff/-/merge_requests/378
Common Vulnerability Exposure (CVE) ID: CVE-2022-2520
https://gitlab.com/libtiff/libtiff/-/issues/424
Common Vulnerability Exposure (CVE) ID: CVE-2022-2521
https://gitlab.com/libtiff/libtiff/-/issues/422
Common Vulnerability Exposure (CVE) ID: CVE-2022-3570
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3570.json
Debian Security Information: DSA-5333 (Google Search)
https://gitlab.com/libtiff/libtiff/-/commit/bd94a9b383d8755a27b5a1bc27660b8ad10b094c
https://gitlab.com/libtiff/libtiff/-/issues/381
https://gitlab.com/libtiff/libtiff/-/issues/386
https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-3598
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3598.json
https://gitlab.com/libtiff/libtiff/-/commit/cfbb883bf6ea7bedcb04177cc4e52d304522fdff
https://gitlab.com/libtiff/libtiff/-/issues/435
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.