Libtiff · Libtiff · CVE-2025-9165
Name of the Vulnerable Software and Affected Versions:
LibTIFF version 4.7.0
Description:
A memory leak issue exists in LibTIFF due to the functions ` TIFFmallocExt`, ` TIFFCheckRealloc`, `TIFFHashSetNew`, and `InitCCITTFax3` within the `tools/tiffcmp.c` file of the `tiffcmp` component. The issue is restricted to local execution.
Recommendations:
Apply the patch ed141286a37f6e5ddafb5069347ff5d587e7a4e0 to resolve this issue.