Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:20801

Опубликовано: 21 мая 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: libtiff security update

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

  • libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM (CVE-2023-52355)

  • libtiff: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service (CVE-2023-52356)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
libtiffi68615.el9_7.2.0.1libtiff-4.4.0-15.el9_7.2.0.1.i686.rpm
libtiffx86_6415.el9_7.2.0.1libtiff-4.4.0-15.el9_7.2.0.1.x86_64.rpm
libtiff-develi68615.el9_7.2.0.1libtiff-devel-4.4.0-15.el9_7.2.0.1.i686.rpm
libtiff-develx86_6415.el9_7.2.0.1libtiff-devel-4.4.0-15.el9_7.2.0.1.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
9 месяцев назад

ELSA-2025-20801: libtiff security update (MODERATE)

CVSS3: 7.5
ubuntu
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
redhat
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
nvd
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

msrc
11 месяцев назад

Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom