ZeroHour

CVE-2022-0907

PoC
CVSS 3.1
5.5 medium
EPSS
1%p68
Published
()
Modified
Description

Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.

Vendors
libtiffdebianfedoraprojectnetapp
Products
libtiff, debian linux, fedora, ontap select deploy administration utility
Weakness
CWE-252
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.