Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TIFF file that triggers a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tiff | Jul 30, 2024 | Jun 24, 2010 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jun 24, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 15, 2010 |
| Suse | — | Upgrade libtiff6Upgrade tiff-docsUpgrade tiffUpgrade libtiff5Upgrade libtiff-develUpgrade libtiff-devel-docsUpgrade libtiff5-32bit | Aug 9, 2024 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libtiff4 | Nov 8, 2024 | Jun 24, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub