Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-17710

Опубликовано: 29 окт. 2025
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2025-17710: compat-libtiff3 security update (IMPORTANT)

[3.9.4-12.0.1]

  • Fixes CVE-2025-9900 buffer underflow [Orabug: 38523840]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

compat-libtiff3

3.9.4-12.0.1.el7

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
redhat
около 2 месяцев назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
nvd
около 2 месяцев назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
msrc
около 1 месяца назад

Libtiff: libtiff write-what-where

CVSS3: 8.8
debian
около 2 месяцев назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where ...