Bug 2387618 (CVE-2025-8851) - CVE-2025-8851 libtiff: LibTIFF Stack-based buffer overflow
Summary: CVE-2025-8851 libtiff: LibTIFF Stack-based buffer overflow
Keywords:
Status: NEW
Alias: CVE-2025-8851
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2387663 2387664 2387665 2387666 2387667 2387668 2387669
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-08-11 14:01 UTC by OSIDB Bzimport
Modified: 2025-08-11 18:26 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-08-11 14:01:22 UTC
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.


Note You need to log in before you can comment on or make changes to this bug.