Описание
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
A flaw was found in libtiff. An attacker can exploit a vulnerability in the process_command_opts() function within tools/tiffcrop.c to execute arbitrary code. This could lead to a complete compromise of the affected system.
Меры по смягчению последствий
Avoid using the tiffcrop utility to process TIFF image files from untrusted sources. If the libtiff-tools package, which provides tiffcrop, is not required, consider removing it to prevent exploitation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libtiff | Affected | ||
| Red Hat Enterprise Linux 6 | libtiff | Out of support scope | ||
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Affected | ||
| Red Hat Enterprise Linux 7 | libtiff | Affected | ||
| Red Hat Enterprise Linux 8 | compat-libtiff3 | Affected | ||
| Red Hat Enterprise Linux 8 | libtiff | Affected | ||
| Red Hat Enterprise Linux 8 | mingw-libtiff | Affected | ||
| Red Hat Enterprise Linux 9 | libtiff | Affected | ||
| Red Hat Hardened Images | libtiff-main-4.7.2-2.hum1 | Fixed | RHSA-2026:53467 | 11.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
Связанные уязвимости
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an ...
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
EPSS
7.3 High
CVSS3