Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libtiffUpgrade libtiff-staticUpgrade libtiff-toolsUpgrade libtiff-debuginfoUpgrade libtiff-tools-debuginfoUpgrade libtiff-develUpgrade libtiff-debugsource | Feb 17, 2025 | Mar 1, 2022 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Mar 28, 2022 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 31, 2022 | Mar 28, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 28, 2022 |
| Suse | — | Upgrade libtiff5Upgrade libtiff-devel-32bitUpgrade libtiff-develUpgrade tiffUpgrade libtiff5-32bit | Oct 26, 2022 | Mar 28, 2022 |
| Ubuntu | — | Upgrade tiffUpgrade tiff (Ubuntu Pro) | Nov 19, 2024 | Mar 28, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub