LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-tiff | Oct 1, 2024 | Jun 26, 2017 | |
| Apple Osx Imageio | apple-osx-security-update-2015-005apple-osx-upgrade-latest | Mar 29, 2016 | Mar 29, 2016 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jun 26, 2017 | |
| Debian | debian-upgrade-tiff | Jul 30, 2024 | Jun 26, 2017 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | Nov 8, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-media-libs-tiff | Oct 30, 2017 | Jun 26, 2017 | |
| Huawei Euleros 2_0_sp1 | huawei-euleros-2_0_sp1-upgrade-compat-libtiff3 | Jan 18, 2018 | Jun 26, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-compat-libtiff3 | Jan 18, 2018 | Jun 26, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-image-library-libtiff-4-0-8-0-175-3-27-0-1-0 | Dec 19, 2017 | Jun 26, 2017 | |
| Ubuntu | ubuntu-upgrade-libtiff4ubuntu-upgrade-libtiff5 | Nov 8, 2024 | Jun 26, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub