In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-tiff | Apr 5, 2018 | Jan 19, 2018 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jan 19, 2018 | |
| Debian | debian-upgrade-tiff | Dec 2, 2018 | Jan 19, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libtiffhuawei-euleros-2_0_sp2-upgrade-libtiff-devel | Nov 3, 2020 | Jan 19, 2018 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-libtiffhuawei-euleros-2_0_sp3-upgrade-libtiff-devel | Sep 28, 2020 | Jan 19, 2018 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-libtiffhuawei-euleros-2_0_sp5-upgrade-libtiff-devel | Sep 3, 2020 | Jan 19, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-image-library-libtiff-4-0-9-11-4-4-0-1-2-0 | Dec 17, 2018 | Jan 19, 2018 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Jan 19, 2018 | |
| Suse | — | suse-upgrade-libtiff-develsuse-upgrade-libtiff5suse-upgrade-libtiff5-32bitsuse-upgrade-tiff | May 10, 2018 | Jan 19, 2018 |
| Ubuntu | ubuntu-upgrade-libtiff-toolsubuntu-upgrade-libtiff5 | Apr 25, 2018 | Jan 19, 2018 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jan 19, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub