CVE-2022-0908 log

Source
Severity Medium
Remote Yes
Type Denial of service
Description
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
Group Package Affected Fixed Severity Status Ticket
AVG-2659 lib32-libtiff 4.3.0-1 4.3.0-2 High Fixed FS#74229
AVG-2658 libtiff 4.3.0-1 4.3.0-2 High Fixed FS#74229
Date Advisory Group Package Severity Type
05 Apr 2022 ASA-202204-6 AVG-2658 libtiff High multiple issues
References
https://gitlab.com/libtiff/libtiff/-/commit/a95b799f65064e4ba2e2dfc206808f86faf93e85
https://gitlab.com/libtiff/libtiff/-/issues/383