CVE-2022-1210

MEDIUM

LibTIFF 4.3.0 - Denial of Service via Malicious TIFF File

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 4.3
EPSS 0.0005
EPSS Percentile 15.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-400 CWE-404
Status published
Products (2)
libtiff/libtiff 4.3.0
netapp/ontap_select_deploy_administration_utility
Published Apr 03, 2022
Tracked Since Feb 18, 2026