CVE-2022-0907 — Unchecked Return Value in Tiff
Severity
5.5MEDIUMNVD
OSV7.5
EPSS
0.2%
top 57.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11
Latest updateSep 12
Description
Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36
Patches
🔴Vulnerability Details
4📋Vendor Advisories
5Microsoft▶
Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the f↗2022-03-08
Debian▶
CVE-2022-0907: tiff - Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 ...↗2022