CVE-2022-48281: Buffer Overflow
Last updated 24 July 2024
Other sources
LibTIFF is vulnerable to a denial of service, caused by a heap-based buffer overflow in the processCropSelections function in tools/tiffcrop.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-48281?
CVE-2022-48281 is a heap-based buffer overflow vulnerability in LibTIFF through version 4.5.0, which can be exploited via a crafted TIFF image.
What is the severity of CVE-2022-48281?
CVE-2022-48281 has a severity rating of 7, which is considered high.
How does CVE-2022-48281 affect Tiff package in Debian?
In Debian, the Tiff package versions 4.1.0+git191117-2~deb10u8, 4.2.0-1+deb11u4, 4.5.0-6, and 4.5.1+git230720-1 are affected by CVE-2022-48281.
How does CVE-2022-48281 affect Tiff package in Ubuntu?
In Ubuntu, the Tiff package versions 4.0.9-5ubuntu0.10+, 4.1.0+, 4.3.0-6ubuntu0.5, 4.0.3-7ubuntu0.11+, 4.5.0-4, and 4.0.6-1ubuntu0.8+ are affected by CVE-2022-48281.
How can I fix CVE-2022-48281?
To fix CVE-2022-48281, update LibTIFF to a version that includes the necessary security patches, such as version 4.5.1+git230720-1 in Debian or version 4.1.0+ in Ubuntu.