CVE-2022-0891
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.1epss 1.5%
exploitation probability
1.5%top 26% of all CVEs
observed exploitation
nono source reports it
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Affected products
libtiff · libtiffReferences
https://gitlab.com/freedesktop-sdk/mirrors/gitlab/libtiff/libtiff/-/commit/232282fd8f9c21eefe8d2d2b96cdbbb172fe7b7chttps://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0891.jsonhttps://gitlab.com/libtiff/libtiff/-/issues/380https://gitlab.com/libtiff/libtiff/-/issues/382https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RNT2GFNRLOMKJ5KXM6JIHKBNBFDVZPD3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQ4E654ZYUUUQNBKYQFXNK2CV3CPWTM2/https://security.gentoo.org/glsa/202210-10https://security.netapp.com/advisory/ntap-20221228-0008/https://www.debian.org/security/2022/dsa-5108