Skip to main content

Divide By Zero

CVE-2005-2452

Severity Medium
Score 5/10

Summary

libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804.

  • LOW
  • NETWORK
  • NONE
  • NONE
  • NONE
  • PARTIAL

CWE-369 - Divide By Zero

The product divides a value by zero.

Advisory Timeline

  • Published