vulnerability
Amazon Linux 2023: CVE-2025-8961: Medium priority package update for libtiff
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 2 | (AV:L/AC:L/Au:S/C:N/I:N/A:P) | Aug 14, 2025 | Oct 16, 2025 | Oct 16, 2025 |
Severity
2
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:P)
Published
Aug 14, 2025
Added
Oct 16, 2025
Modified
Oct 16, 2025
Description
A vulnerability was identified in LibTIFF 4.7.0. This issue affects the function May of the file tiffcrop.c of the component tiffcrop. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Solutions
amazon-linux-2023-upgrade-libtiffamazon-linux-2023-upgrade-libtiff-debuginfoamazon-linux-2023-upgrade-libtiff-debugsourceamazon-linux-2023-upgrade-libtiff-develamazon-linux-2023-upgrade-libtiff-staticamazon-linux-2023-upgrade-libtiff-toolsamazon-linux-2023-upgrade-libtiff-tools-debuginfo
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.