LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools/bmp2tiff.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tiff | May 15, 2025 | May 15, 2025 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 30, 2017 | Jan 23, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libtiff-develUpgrade libtiff | Dec 4, 2019 | Jan 23, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libtiff-develUpgrade libtiff | Apr 30, 2021 | Jan 23, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade compat-libtiff3 | Mar 24, 2021 | Jan 23, 2017 |
| Oracle Solaris | — | Upgrade image/library/libtiff to version 4.0.8-0.175.3.27.0.1.0 on Solaris 11.3 | Dec 19, 2017 | Jan 23, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 18, 2017 |
| Ubuntu | — | Upgrade libtiff5Upgrade libtiff-tools | Apr 25, 2018 | Jan 23, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub