Impact
A flaw in iccDEV’s TIFF image reader causes a division by zero when parsing certain TIFF files, which can crash the host process. The crash results in a denial of service for any application that relies on the library. The vulnerability falls under CWE-20 (Improper Input Validation) and CWE-369 (Divide by Zero).
Affected Systems
International Color Consortium’s iccDEV library, versions prior to 2.3.1.2, is affected. Any system that uses a vulnerable iteration of iccDEV and processes TIFF images is at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: a malicious TIFF file can be supplied by any user or application that loads the library, triggering a crash without requiring network access or special privileges.
OpenCVE Enrichment