A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.
CVSS Details
- CVSS 4.0 Base Score: 1.9 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tiff | Sep 22, 2025 | Aug 14, 2025 |
| Amazon Linux Ami 2 | — | Upgrade libtiff-staticUpgrade compat-libtiff3Upgrade libtiff-debuginfoUpgrade compat-libtiff3-debuginfoUpgrade libtiffUpgrade libtiff-develUpgrade libtiff-tools | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade libtiff-tools-debuginfoUpgrade libtiffUpgrade libtiff-debugsourceUpgrade libtiff-develUpgrade libtiff-toolsUpgrade libtiff-debuginfoUpgrade libtiff-static | Oct 16, 2025 | Aug 14, 2025 |
| Debian | — | Upgrade tiff | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Aug 14, 2025 |
| Suse | — | Upgrade tiffUpgrade libtiff6-32bitUpgrade libtiff5-32bitUpgrade libtiff-develUpgrade libtiff5Upgrade libtiff-devel-32bitUpgrade libtiff6 | Dec 5, 2025 | Sep 24, 2025 |
| Ubuntu | — | Upgrade libtiff5 (Ubuntu Pro)Upgrade libtiff5Upgrade libtiff6 | Sep 30, 2025 | Aug 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub