Candidate: CVE-2022-0924 PublicDate: 2022-03-11 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0924 https://gitlab.com/libtiff/libtiff/-/issues/278 https://gitlab.com/libtiff/libtiff/-/merge_requests/311 https://gitlab.com/libtiff/libtiff/-/commit/88d79a45a31c74cba98c697892fed5f7db8b963a https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0924.json Description: Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_tiff: upstream_tiff: released (4.3.0-6) trusty/esm_tiff: needs-triage esm-infra/xenial_tiff: needs-triage trusty_tiff: ignored (out of standard support) xenial_tiff: ignored (out of standard support) bionic_tiff: needs-triage focal_tiff: needs-triage impish_tiff: needs-triage jammy_tiff: needs-triage devel_tiff: needs-triage