CVE-2022-40090 — Infinite Loop in Libtiff
Severity
6.5MEDIUMNVD
EPSS
0.0%
top 98.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateNov 23
Description
An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages1 packages
Patches
🔴Vulnerability Details
4CVEList
▶
GHSA▶
GHSA-279f-f7v7-h5h8: An issue was discovered in function TIFFReadDirectory libtiff before 4↗2023-08-22
OSV
▶