CVE Database
/

CVE-2022-2867

Back to search

CVE-2022-2867

Published: Aug 17, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation.

VendorProductVersions

n/a

libtiff

affected
libtiff 4.4.0rc1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now