Medium severity6.8NVD Advisory· Published Mar 3, 2023· Updated Jun 17, 2026
CVE-2022-4645
CVE-2022-4645
Description
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- osv-coords3 versions
< 4.4.0-7.el9+ 2 more
- (no CPE)range: < 4.4.0-7.el9
- (no CPE)range: < 4.4.0-7.el9
- (no CPE)range: < 4.4.0-7.el9
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- gitlab.com/libtiff/libtiff/-/commit/e813112545942107551433d61afd16ac094ff246nvdPatch
- gitlab.com/libtiff/libtiff/-/issues/277nvdExploitIssue TrackingVendor Advisory
- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4645.jsonnvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZTFA6GGOKFPIQNHDBMXYUR4XUXUJESE/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BA6GRCAQ7NR2OK5N44UQRGUJBIYKWJJH/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLM763GGZVVOAXIQXG6YGTYJ5VFYNECQ/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20230331-0001/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.