Alpine: libtiffxx, multiple tiff packages: security update to 4.5.0-r0

high Tenable Cloud Security Plugin ID 424545

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function
TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is
possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to
fix this issue. The identifier VDB-213549 was assigned to this vulnerability. (CVE-2022-3970)

- LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing
attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from
sources, the fix is available with commit 48d6ece8. (CVE-2022-2953)

- A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF
file, it could lead to undefined behavior or a crash causing a denial of service. (CVE-2022-3213)

- Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to
trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into
application crash, potential information disclosure or any other context-dependent impact (CVE-2022-3570)

- LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from
extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted
tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
(CVE-2022-3597)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-2953

https://security.alpinelinux.org/vuln/CVE-2022-3213

https://security.alpinelinux.org/vuln/CVE-2022-3570

https://security.alpinelinux.org/vuln/CVE-2022-3597

https://security.alpinelinux.org/vuln/CVE-2022-3598

https://security.alpinelinux.org/vuln/CVE-2022-3599

https://security.alpinelinux.org/vuln/CVE-2022-3626

https://security.alpinelinux.org/vuln/CVE-2022-3627

https://security.alpinelinux.org/vuln/CVE-2022-3970

Plugin Details

Severity: High

ID: 424545

Version: Revision 1.7

Type: Local

Published: 4/4/2025

Updated: 5/30/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-3970

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 8/29/2022

Reference Information

CVE: CVE-2022-2953, CVE-2022-3213, CVE-2022-3570, CVE-2022-3597, CVE-2022-3598, CVE-2022-3599, CVE-2022-3626, CVE-2022-3627, CVE-2022-3970