Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Appkit | — | Apply OS X security update 2005-005 | Dec 16, 2011 | Jan 10, 2005 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Jan 10, 2005 |
| Freebsd | — | Upgrade ja-ivUpgrade pdflibUpgrade tiffUpgrade pdflib-perlUpgrade gdalUpgrade ivUpgrade paraviewUpgrade linux-tiffUpgrade ja-libimgUpgrade fractoramaUpgrade ivtools | Dec 10, 2025 | Jan 6, 2005 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jan 10, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub