CVE-2022-0562

MEDIUM

libtiff 4.0-4.3.0 - Denial of Service via Crafted TIFF File

Title source: llm
STIX 2.1

Description

Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c.

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 9.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (6)
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 35
libtiff/libtiff 4.0.0 - 4.3.0
netapp/ontap_select_deploy_administration_utility
Published Feb 11, 2022
Tracked Since Feb 18, 2026