← Back

CVE-2022-3970

nvd nist
Published: Nov 13, 2022Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.

Affected (7)

Show all products
1 product
Libtiff
1 product
Active Iq Unified Manager
1 product
Debian Linux
4 products
Ipados
Iphone Os
Macos
Safari
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.5.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Before 16.6
Before 16.6
Before 13.5
Before 16.5.1

Related CWEs

References (16)

Source: cna@vuldb.com
ExploitIssue TrackingThird Party Advisory
Source: cna@vuldb.com
Mailing ListThird Party Advisory
Source: cna@vuldb.com
Third Party Advisory
Source: cna@vuldb.com
Release NotesThird Party Advisory
Source: cna@vuldb.com
Release NotesThird Party Advisory
Source: cna@vuldb.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.