In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tiff | May 15, 2025 | May 15, 2025 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libtiffUpgrade libtiff-devel | Dec 4, 2019 | May 21, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libtiffUpgrade libtiff-devel | Apr 30, 2021 | May 21, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libtiffUpgrade libtiff-devel | Nov 19, 2019 | May 21, 2017 |
| Oracle Solaris | — | Upgrade image/library/libtiff to version 4.0.8-0.175.3.27.0.1.0 on Solaris 11.3 | Dec 19, 2017 | May 21, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 7, 2017 |
| Suse | — | Upgrade libtiff-develUpgrade libtiff3-x86Upgrade libtiff3-32bitUpgrade libtiff3Upgrade libtiff-devel-32bitUpgrade tiff | Nov 24, 2018 | May 21, 2017 |
| Ubuntu | — | Upgrade libtiff-toolsUpgrade libtiff5 | Apr 25, 2018 | May 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub