Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-17675

Опубликовано: 09 окт. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-17675: compat-libtiff3 security update (IMPORTANT)

[3.9.4-14]

  • fix CVE-2025-9900: Write-What-Where via TIFFReadRGBAImageOriented (RHEL-112528)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

compat-libtiff3

3.9.4-14.el8_10

Oracle Linux x86_64

compat-libtiff3

3.9.4-14.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
2 месяца назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
redhat
2 месяца назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
nvd
2 месяца назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
msrc
2 месяца назад

Libtiff: libtiff write-what-where

CVSS3: 8.8
debian
2 месяца назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where ...