Vulnerabilities > CVE-2022-2521 - Release of Invalid Pointer or Reference vulnerability in multiple products

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
libtiff
debian
CWE-763

Summary

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input.

Vulnerable Configurations

Part Description Count
Application
Libtiff
1
OS
Debian
1

Common Weakness Enumeration (CWE)