Medium severity5.5NVD Advisory· Published Aug 29, 2022· Updated Jun 17, 2026
CVE-2022-2953
CVE-2022-2953
Description
LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords3 versions
< 4.0.9-26.el8_7+ 2 more
- (no CPE)range: < 4.0.9-26.el8_7
- (no CPE)range: < 4.0.9-26.el8_7
- (no CPE)range: < 4.0.9-26.el8_7
- cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- gitlab.com/libtiff/libtiff/-/commit/48d6ece8389b01129e7d357f0985c8f938ce3da3nvdPatch
- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2953.jsonnvdExploitIssue TrackingPatchVDB Entry
- gitlab.com/libtiff/libtiff/-/issues/414nvdExploitIssue TrackingPatchThird Party Advisory
- security.netapp.com/advisory/ntap-20221014-0008/nvdThird Party Advisory
- www.debian.org/security/2023/dsa-5333nvdThird Party Advisory
News mentions
0No linked articles in our index yet.