Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libtiff-develUpgrade libtiff-tools-debuginfoUpgrade libtiff-debuginfoUpgrade libtiff-debugsourceUpgrade libtiff-toolsUpgrade libtiff-staticUpgrade libtiff | Feb 17, 2025 | Mar 1, 2022 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Mar 28, 2022 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 31, 2022 | Mar 28, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 28, 2022 |
| Suse | — | Upgrade libtiff-devel-32bitUpgrade libtiff-develUpgrade libtiff5Upgrade tiffUpgrade libtiff5-32bit | Oct 26, 2022 | Mar 28, 2022 |
| Ubuntu | — | Upgrade tiff (Ubuntu Pro)Upgrade tiff | Nov 19, 2024 | Mar 28, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub