PT-2025-39179 · Libtiff+10 · Libtiff+10

Published

2025-01-01

·

Updated

2026-05-28

·

CVE-2025-9900

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF versions prior to 4.7.0 LibTIFF version 4.7.0
Description A flaw exists in LibTIFF that results in a "write-what-where" condition. This issue is triggered when the library processes a specially crafted TIFF image file. An attacker can provide an abnormally large image height value in the file's metadata, which tricks the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can lead to a denial of service (application crash) or potentially allow for arbitrary code execution with the permissions of the user. The issue is present in versions using the TIFFReadRGBAImage or TIFFReadRGBAImageOriented functions with a smaller height than the actual TIFF image height.
Recommendations For versions prior to 4.7.0, update to version 4.7.0 or later. For version 4.7.0, ensure that the image height used in TIFFReadRGBAImage or TIFFReadRGBAImageOriented matches the actual TIFF image height to prevent potential exploitation.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2025:17675
ALSA-2025:19113
ALSA-2025:19156
ALSA-2025:19276
ALSA-2025:19906
ALSA-2025:20956
ALSA-2025:20998
ALT-PU-2025-11954
ALT-PU-2025-12863
ALT-PU-2025-12867
ALT-PU-2025-13034
AZL-67722
AZL-67739
AZL-67794
AZL-67803
BDU:2025-13921
CESA-2025_17675
CESA-2025_19276
CESA-2025_19906
CVE-2025-9900
DLA-4315-1
DSA-6023-1
ECHO-0EC2-A434-C824
INFSA-2025_17675
INFSA-2025_19113
INFSA-2025_19276
INFSA-2025_19906
INFSA-2025_20956
MGASA-2025-0252
OESA-2025-2400
OESA-2025-2401
OESA-2025-2402
OESA-2025-2403
OESA-2025-2404
OESA-2025-2405
OPENSUSE-SU-2025:15635-1
OPENSUSE-SU-2025:20049-1
RHSA-2025:17651
RHSA-2025:17675
RHSA-2025:17710
RHSA-2025:17738
RHSA-2025:17739
RHSA-2025:17740
RHSA-2025:19113
RHSA-2025:19156
RHSA-2025:19276
RHSA-2025:19906
RHSA-2025:19947
RHSA-2025:20956
RHSA-2025:20998
RHSA-2025:21060
RHSA-2025:21061
RHSA-2025:21062
RHSA-2025:21506
RHSA-2025_17675
RHSA-2025_19113
RHSA-2025_19276
RHSA-2025_19906
RHSA-2025_20956
RHSA-2026:0001
RHSA-2026:0076
RHSA-2026:0077
RHSA-2026:0078
RHSA-2026:7504
SUSE-SU-2025:20971-1
SUSE-SU-2025:21009-1
SUSE-SU-2025:21032-1
SUSE-SU-2025:21037-1
SUSE-SU-2025:3941-1
SUSE-SU-2025:3957-1
SUSE-SU-2025:3961-1
SUSE-SU-2025_3941-1
SUSE-SU-2025_3961-1
USN-7783-1
USN-8345-1
USN-8346-1
USN-8347-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Libtiff
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu