LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libtiff-staticUpgrade libtiff-debuginfoUpgrade libtiff-debugsourceUpgrade libtiff-toolsUpgrade libtiff-develUpgrade libtiffUpgrade libtiff-tools-debuginfo | Feb 17, 2025 | May 11, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 11, 2022 |
| Debian | — | Upgrade tiff | Jan 31, 2023 | May 11, 2022 |
| Gentoo Linux | — | Upgrade media-libs/tiff. | Oct 31, 2022 | May 11, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 11, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub