CVE-2022-0909 — Divide By Zero in Tiff
Severity
5.5MEDIUMNVD
OSV7.5
EPSS
0.2%
top 57.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11
Latest updateSep 12
Description
Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36
Patches
🔴Vulnerability Details
4📋Vendor Advisories
5Microsoft▶
Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit f8↗2022-03-08
Debian▶
CVE-2022-0909: tiff - Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a de...↗2022