CVE-2022-2056 — Divide By Zero in Tiff
Severity
6.5MEDIUMNVD
OSV7.5
EPSS
0.1%
top 74.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateSep 20
Description
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages9 packages
Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36
Patches
🔴Vulnerability Details
3📋Vendor Advisories
4Microsoft▶
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit f3↗2022-06-14
Debian▶
CVE-2022-2056: tiff - Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a de...↗2022