CVE-2022-40090Infinite Loop in Libtiff

CWE-835Infinite Loop8 documents7 sources
Severity
6.5MEDIUMNVD
EPSS
0.0%
top 98.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateNov 23

Description

An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDlibtiff/libtiff< 4.4.0

Patches

🔴Vulnerability Details

4
OSV
tiff vulnerabilities2023-11-23
CVEList
CVE-2022-40090: An issue was discovered in function TIFFReadDirectory libtiff before 42023-08-22
GHSA
GHSA-279f-f7v7-h5h8: An issue was discovered in function TIFFReadDirectory libtiff before 42023-08-22
OSV
CVE-2022-40090: An issue was discovered in function TIFFReadDirectory libtiff before 42023-08-22

📋Vendor Advisories

3
Ubuntu
LibTIFF vulnerabilities2023-11-23
Red Hat
libtiff: infinite loop via a crafted TIFF file2022-08-22
Debian
CVE-2022-40090: tiff - An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allow...2022