CVE-2022-0909: Divide by Zero
Published Mar 11, 2022
·Updated
Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.
Affected Software
7 affected componentsFixes available
debian/tiff
4.1.0+git191117-2~deb10u44.1.0+git191117-2~deb10u84.2.0-1+deb11u44.5.0-64.5.1+git230720-1
LibTIFF libtiff=4.3.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=35
Fedoraproject Fedora=36
NetApp ONTAP Select Deploy administration utility
Remediation
Patch Available
Event History
Mar 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Mar 15, 2022
Data Sourced
via Red Hat·07:14 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-0909?
CVE-2022-0909 has been categorized as a denial-of-service vulnerability.
2
How do I fix CVE-2022-0909?
To fix CVE-2022-0909, users should update to a patched version of libtiff or apply the fix available in commit f8d0f9aa.
3
Which versions of libtiff are affected by CVE-2022-0909?
CVE-2022-0909 affects libtiff version 4.3.0 and potentially earlier versions.
4
What is the impact of CVE-2022-0909?
The impact of CVE-2022-0909 includes the possibility of triggering a Divide By Zero error that leads to a denial-of-service.
5
Can CVE-2022-0909 be exploited through a tiff file?
Yes, CVE-2022-0909 can be exploited by using a specially crafted tiff file.