Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-9165

Опубликовано: 19 авг. 2025
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 1
CVSS3: 2.5

Описание

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".

РелизСтатусПримечание
devel

not-affected

uses system tiff
esm-apps/bionic

not-affected

uses system tiff
esm-apps/focal

not-affected

uses system tiff
esm-apps/jammy

not-affected

uses system tiff
esm-apps/noble

not-affected

uses system tiff
esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needs-triage

jammy

not-affected

uses system tiff
noble

not-affected

uses system tiff
plucky

not-affected

uses system tiff

Показывать по

РелизСтатусПримечание
devel

not-affected

dropped embedded libtiff
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

dropped embedded libtiff
jammy

needs-triage

noble

not-affected

dropped embedded libtiff
plucky

not-affected

dropped embedded libtiff
questing

not-affected

dropped embedded libtiff
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

jammy

needs-triage

noble

needs-triage

plucky

needs-triage

questing

needs-triage

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/xenial

needs-triage

jammy

needs-triage

noble

needs-triage

plucky

needs-triage

questing

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

4.7.0-3ubuntu3
esm-infra-legacy/trusty

released

4.0.3-7ubuntu0.11+esm16
esm-infra/bionic

released

4.0.9-5ubuntu0.10+esm9
esm-infra/focal

released

4.1.0+git191117-2ubuntu0.20.04.14+esm2
esm-infra/xenial

released

4.0.6-1ubuntu0.8+esm19
jammy

released

4.3.0-6ubuntu0.12
noble

released

4.5.1+git230720-4ubuntu2.4
plucky

released

4.5.1+git230720-4ubuntu4.2
questing

released

4.7.0-3ubuntu3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 5%
0.00024
Низкий

1 Low

CVSS2

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
redhat
около 2 месяцев назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue.

CVSS3: 2.5
nvd
около 2 месяцев назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".

CVSS3: 2.5
debian
около 2 месяцев назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIF ...

CVSS3: 3.3
github
около 2 месяцев назад

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue.

CVSS3: 3.3
fstec
2 месяца назад

Уязвимость компонента tiffcmp библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00024
Низкий

1 Low

CVSS2

2.5 Low

CVSS3

Уязвимость CVE-2025-9165