CVE-2022-0907Unchecked Return Value in Tiff

Severity
5.5MEDIUMNVD
OSV7.5
EPSS
0.2%
top 57.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11
Latest updateSep 12

Description

Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5libtiff/libtiff=4.3.0
NVDlibtiff/libtiff4.3.0
debiandebian/tiff< tiff 4.3.0-6 (bookworm)

Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36

Patches

🔴Vulnerability Details

4
OSV
tiff vulnerabilities2022-09-12
OSV
tiff vulnerabilities2022-07-19
GHSA
GHSA-6q3c-x5wm-6w9c: Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 42022-03-12
OSV
CVE-2022-0907: Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 42022-03-11

📋Vendor Advisories

5
Ubuntu
LibTIFF vulnerabilities2022-09-12
Ubuntu
LibTIFF vulnerabilities2022-07-19
Red Hat
tiff: NULL Pointer Dereference in tiffcrop2022-03-11
Microsoft
Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the f2022-03-08
Debian
CVE-2022-0907: tiff - Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 ...2022