NULL pointer dereference in LibTIFF - CVE-2022-0907

 

NULL pointer dereference in LibTIFF - CVE-2022-0907

Published: May 30, 2022


Vulnerability identifier: #VU63794
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0907
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in tiffcrop in libtiff. A remote attacker can trigger denial of service conditions via a crafted tiff file.


Affected software

LibTIFF
Amazon Linux AMI
Debian Linux
Gentoo Linux
Arch Linux
Ubuntu
openEuler
Fedora
Tanzu Greenplum for Kubernetes
VMware Tanzu Operations Manager
libtiff
libtiff-opengl (Ubuntu package)
libtiff-tools (Ubuntu package)
libtiffxx5 (Ubuntu package)
libtiff5 (Ubuntu package)
tiff (Debian package)
libtiff-debuginfo
libtiff-devel
libtiff-debugsource
libtiff-help
media-libs/tiff

How to mitigate CVE-2022-0907

Install update from vendor's website.

LibTIFF - update to 4.4.0
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
libtiff - addressed in versions 4.0.3-35.38, 4.4.0-4
libtiff-opengl (Ubuntu package) - addressed in versions 4.0.9-5ubuntu0.6, 4.0.61ubuntu0.8+esm2, 4.1.0+git191117-2ubuntu0.20.04.4
libtiff-tools (Ubuntu package) - addressed in versions 4.0.9-5ubuntu0.6, 4.0.61ubuntu0.8+esm2, 4.1.0+git191117-2ubuntu0.20.04.4
libtiffxx5 (Ubuntu package) - addressed in versions 4.0.9-5ubuntu0.6, 4.0.61ubuntu0.8+esm2, 4.1.0+git191117-2ubuntu0.20.04.4
libtiff5 (Ubuntu package) - addressed in versions 4.0.9-5ubuntu0.6, 4.0.61ubuntu0.8+esm2, 4.1.0+git191117-2ubuntu0.20.04.4
tiff (Debian package) - addressed in versions 4.1.0+git191117-2~deb10u4, 4.2.0-1+deb11u1
libtiff - update to 4.1.0-10
libtiff-debuginfo - update to 4.1.0-10
libtiff-devel - update to 4.1.0-10
libtiff-debugsource - update to 4.1.0-10
libtiff-help - update to 4.1.0-10
libtiff - update to 4.3.0-2
libtiff - addressed in versions 4.3.0-5.fc36, 4.3.0-6.fc35, 4.3.0-6.fc36
media-libs/tiff - update to 4.4.0

External References

Related Security Bulletins