CVE-2022-0562: Null Pointer Dereference
LibTIFF is vulnerable to a denial of service, caused by a NULL pointer dereference in the memcpy() function in TIFFReadDirectory() in tifdirread.c. A local authenticated attacker could exploit this vulnerability to cause a denial of service.
Other sources
Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tifdirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0562?
CVE-2022-0562 has a severity rating that indicates it can lead to a denial of service due to a null pointer dereference.
How do I fix CVE-2022-0562?
To fix CVE-2022-0562, apply the latest patches or updates available for the affected software, specifically for LibTIFF and IBM Cognos Analytics.
Which versions of tiff are vulnerable to CVE-2022-0562?
Versions of tiff prior to 4.1.0+git191117-2~deb10u4 and up to 4.2.0-1+deb11u4 are vulnerable to CVE-2022-0562.
Who is affected by CVE-2022-0562?
Local authenticated attackers can exploit CVE-2022-0562 in systems running affected versions of LibTIFF and Cognos Analytics.
What impact does CVE-2022-0562 have on systems?
The impact of CVE-2022-0562 includes potential denial of service, allowing attackers to disrupt application availability.