PT-2026-21538 · Libtiff · Libtiff

Published

2025-01-01

·

Updated

2026-04-06

·

CVE-2025-61145

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libtiff versions up to 4.7.1
Description The libtiff software contains a double free issue within the tools/tiffcrop.c component. This condition can be triggered, potentially leading to a denial-of-service or other unexpected behavior.
Recommendations Update to a version of libtiff newer than 4.7.1.

Exploit

Fix

Double Free

Weakness Enumeration

Related Identifiers

AZL-78314
AZL-78333
CVE-2025-61145
ECHO-400A-DE0A-4538
OESA-2026-1441
OESA-2026-1442
RHSA-2026:7504

Affected Products

Libtiff