Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-8176

Опубликовано: 26 июл. 2025
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.3

Описание

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.

РелизСтатусПримечание
devel

released

4.7.0-3ubuntu2
esm-infra-legacy/trusty

released

4.0.3-7ubuntu0.11+esm15
esm-infra/bionic

released

4.0.9-5ubuntu0.10+esm8
esm-infra/focal

released

4.1.0+git191117-2ubuntu0.20.04.14+esm1
esm-infra/xenial

released

4.0.6-1ubuntu0.8+esm18
jammy

released

4.3.0-6ubuntu0.11
noble

released

4.5.1+git230720-4ubuntu2.3
plucky

released

4.5.1+git230720-4ubuntu4.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 3%
0.00017
Низкий

4.3 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
3 месяца назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.

CVSS3: 5.3
nvd
3 месяца назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.

CVSS3: 5.3
debian
3 месяца назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared ...

CVSS3: 5.3
github
3 месяца назад

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.

suse-cvrf
2 месяца назад

Security update for tiff

EPSS

Процентиль: 3%
0.00017
Низкий

4.3 Medium

CVSS2

5.3 Medium

CVSS3