CVE-2022-2056: Divide by Zero
A divide-by-zero vulnerability was found in libtiff. This flaw allows an attacker to cause a denial of service via a crafted tiff file.
Other sources
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
LibTIFF is vulnerable to a denial of service, caused by a divide-by-zero error in tiffcrop. By persuading a victim to open a specially-crafted TIFF file, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-2056?
CVE-2022-2056 is a divide-by-zero vulnerability found in libtiff.
How does CVE-2022-2056 affect users?
CVE-2022-2056 allows attackers to cause a denial-of-service by exploiting a Divide By Zero error in the tiffcrop utility of libtiff.
Which versions of libtiff are affected by CVE-2022-2056?
Versions 4.1.0+git191117-2~deb10u4, 4.4.0-5.el9_1, and 4.0.9-26.el8_7 of libtiff are affected by CVE-2022-2056.
How can I fix CVE-2022-2056 in libtiff?
For users compiling libtiff from sources, the fix is available with commit f3a5e010.
What is the severity of CVE-2022-2056?
CVE-2022-2056 has a severity score of 5.1 (high).