Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9900

Опубликовано: 22 сент. 2025
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

Отчет

This attack requires user interaction to run the malicious TIFF image file, hence the CVE is maintained as important.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libtiffAffected
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Affected
Red Hat Enterprise Linux 7libtiffAffected
Red Hat Enterprise Linux 8compat-libtiff3Affected
Red Hat Enterprise Linux 8libtiffAffected
Red Hat Enterprise Linux 8mingw-libtiffAffected
Red Hat Enterprise Linux 9libtiffAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-123

EPSS

Процентиль: 22%
0.00069
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
22 дня назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

CVSS3: 8.8
nvd
22 дня назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

msrc
19 дней назад

Libtiff: libtiff write-what-where

CVSS3: 8.8
debian
22 дня назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where ...

CVSS3: 8.8
github
22 дня назад

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

EPSS

Процентиль: 22%
0.00069
Низкий

8.8 High

CVSS3