CVE-2022-0907: Null Pointer Dereference
Published Mar 11, 2022
·Updated
Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.
Affected Software
7 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.3.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=35
Fedoraproject Fedora=36
NetApp ONTAP Select Deploy administration utility
Remediation
Patch Available
Event History
Mar 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-0907.
2
What is the severity rating of CVE-2022-0907?
The severity rating of CVE-2022-0907 is 5.5 (medium).
3
How does the vulnerability CVE-2022-0907 occur?
The vulnerability CVE-2022-0907 occurs due to an unchecked return value to NULL pointer dereference in tiffcrop in libtiff 4.3.0.
4
What is the impact of CVE-2022-0907?
The impact of CVE-2022-0907 is a denial-of-service (DoS) attack caused by a crafted tiff file.
5
How can I fix CVE-2022-0907?
For users that compile libtiff from sources, the fix is available with commit f2b656e2.