Wind River Support Network

HomeDefectsLIN1021-2823
Fixed

LIN1021-2823 : Security Advisory - tiff - CVE-2022-0562

Created: Feb 13, 2022    Updated: Mar 27, 2022
Resolved Date: Mar 27, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.11
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c.

CREATE(Triage):(User=admin) CVE-2022-0562 (https://nvd.nist.gov/vuln/detail/CVE-2022-0562)

CVEs


Live chat
Online