Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c.
[
{
"source": "https://gitlab.com/gitlab-org/build/omnibus-mirror/libtiff@561599c99f987dc32ae110370cfdd7df7975586b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "129003738256904974434032312831734533679",
"length": 17287.0
},
"target": {
"function": "TIFFReadDirectory",
"file": "libtiff/tif_dirread.c"
},
"id": "CVE-2022-0562-5e6decd3"
},
{
"source": "https://gitlab.com/gitlab-org/build/omnibus-mirror/libtiff@561599c99f987dc32ae110370cfdd7df7975586b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"222657081805446374098817547520940382651",
"46343763023096549359691253295778653557",
"8490074471616727942160351420981319456",
"262687486300517843764821785466064460"
]
},
"target": {
"file": "libtiff/tif_dirread.c"
},
"id": "CVE-2022-0562-acf8b664"
}
]