Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libtiff-debuginfoUpgrade libtiff-debugsourceUpgrade libtiff-develUpgrade libtiff-tools-debuginfoUpgrade libtiffUpgrade libtiff-toolsUpgrade libtiff-static | Feb 17, 2025 | Mar 1, 2022 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | Mar 28, 2022 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 31, 2022 | Mar 28, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 28, 2022 |
| Suse | — | Upgrade libtiff5-32bitUpgrade tiffUpgrade libtiff5Upgrade libtiff-develUpgrade libtiff-devel-32bit | Oct 26, 2022 | Mar 28, 2022 |
| Ubuntu | — | Upgrade tiff (Ubuntu Pro)Upgrade tiff | Nov 19, 2024 | Mar 28, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 28, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub