Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libtiffUpgrade libtiff-devel | Dec 1, 2016 | Jul 14, 2009 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Jul 14, 2009 |
| Freebsd | — | Upgrade tiffUpgrade linux-f10-tiffUpgrade linux-tiff | Dec 10, 2025 | Jun 16, 2010 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jul 14, 2009 |
| Oracle_linux | — | Upgrade libtiff-develUpgrade libtiff | Oct 16, 2024 | Jul 14, 2009 |
| Suse | — | Upgrade libtiff3-x86Upgrade tiffUpgrade libtiff3-32bitUpgrade libtiff3Upgrade libtiff5-32bitUpgrade tiff-docsUpgrade libtiff6Upgrade libtiff-devel-docsUpgrade libtiff-devel-32bitUpgrade libtiff-develUpgrade libtiff5 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libtiff4 | Nov 8, 2024 | Jul 14, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub