PT-2022-6484 · Libtiff+9 · Libtiff+9

4Ugustus

+1

·

Published

2022-06-30

·

Updated

2025-06-19

·

CVE-2022-2056

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libtiff version 4.4.0
Description The issue is related to a Divide By Zero error in the tiffcrop function of libtiff, which can be exploited by attackers to cause a denial-of-service via a crafted tiff file. This can be achieved by a remote attacker.
Recommendations For libtiff version 4.4.0, users who compile libtiff from sources can apply the fix available with commit f3a5e010.

Exploit

Fix

DoS

Divide By Zero

Weakness Enumeration

Related Identifiers

ALSA-2023:0095
ALSA-2023:0302
ALSA-2023_0095
ALSA-2023_0302
ALT-PU-2022-3360
ALT-PU-2022-3428
ALT-PU-2025-7185
ALT-PU-2025-7532
AZL-10007
AZL-44847
BDU:2023-01715
CESA-2023_0095
CVE-2022-2056
DLA-3278-1
DSA-5333-1
MGASA-2022-0267
OESA-2022-2007
OPENSUSE-SU-2022_2647-1
OPENSUSE-SU-2024:12176-1
RHSA-2023:0095
RHSA-2023:0302
RHSA-2023_0095
RHSA-2023_0302
RLSA-2023:0095
RLSA-2023:0302
SUSE-SU-2022:2647-1
SUSE-SU-2022:2647-2
SUSE-SU-2022:2648-1
SUSE-SU-2022_2647-1
SUSE-SU-2022_2648-1
USN-5619-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Libtiff