CVE-2022-40090: Medium severity IBM Cognos Analytics vulnerability
An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.
Other sources
libtiff is vulnerable to a denial of service, caused by an infinite loop flaw in the TIFFReadDirectory function. By persuading a victim to open a specially crafted TIFF file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-40090?
CVE-2022-40090 is an issue discovered in the TIFFReadDirectory function of libtiff before version 4.4.0, which allows attackers to cause a denial of service by exploiting a crafted TIFF file.
How does CVE-2022-40090 impact libtiff?
CVE-2022-40090 can lead to a denial of service attack on libtiff versions prior to 4.4.0 when processing specially crafted TIFF files.
What is the severity of CVE-2022-40090?
The severity of CVE-2022-40090 is medium, with a CVSS severity score of 6.5.
How can I fix CVE-2022-40090?
To fix CVE-2022-40090, you should upgrade to libtiff version 4.4.0 or later, which contains a fix for this vulnerability.
Are there any references for CVE-2022-40090?
Yes, you can find more information about CVE-2022-40090 in the following references: [link1](https://gitlab.com/libtiff/libtiff/-/issues/455), [link2](https://gitlab.com/libtiff/libtiff/-/merge_requests/386).