CVE-2022-2058: Divide by Zero
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
Other sources
LibTIFF is vulnerable to a denial of service, caused by a divide-by-zero error in tiffcrop. By persuading a victim to open a specially-crafted TIFF file, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-2058.
What is the title of the vulnerability?
The title of the vulnerability is 'Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file.'
What is the severity of the vulnerability?
The severity of the vulnerability is not specified.
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by using a crafted tiff file to cause a Divide By Zero error in tiffcrop, resulting in a denial-of-service condition.
How can I fix this vulnerability?
For users that compile libtiff from sources, the fix is available with commit f3a5e010.