Количество 15
Количество 15
BDU:2025-09847
Уязвимость функции PS_Lvl2page() библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании
ALT-PU-2025-10179
ALT-PU-2025-10179: package `libtiff` update to version 4.4.0-alt6
ALT-PU-2025-11213
ALT-PU-2025-11213: package `libtiff5` update to version 4.4.0-alt7
ROS-20251105-02
Множественные уязвимости libtiff
CVE-2025-8534
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."
CVE-2025-8534
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."
CVE-2025-8534
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."
CVE-2025-8534
libtiff tiff2ps tiff2ps.c PS_Lvl2page null pointer dereference
CVE-2025-8534
A vulnerability classified as problematic was found in libtiff 4.6.0. ...
ALT-PU-2025-11954
ALT-PU-2025-11954: package `libtiff` update to version 4.7.1-alt1
GHSA-xgh3-993q-r2x8
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."
SUSE-SU-2025:03346-1
Security update for tiff
SUSE-SU-2025:03345-1
Security update for tiff
SUSE-SU-2025:03348-1
Security update for tiff
openSUSE-SU-2025:20049-1
Security update for tiff
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2025-09847 Уязвимость функции PS_Lvl2page() библиотеки LibTIFF, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 2.5 | 0% Низкий | около 1 года назад | |
ALT-PU-2025-10179 ALT-PU-2025-10179: package `libtiff` update to version 4.4.0-alt6 | CVSS3: 7.8 | около 1 года назад | ||
ALT-PU-2025-11213 ALT-PU-2025-11213: package `libtiff5` update to version 4.4.0-alt7 | CVSS3: 7.8 | около 1 года назад | ||
ROS-20251105-02 Множественные уязвимости libtiff | CVSS3: 8.8 | 11 месяцев назад | ||
CVE-2025-8534 A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used." | CVSS3: 2.5 | 0% Низкий | около 1 года назад | |
CVE-2025-8534 A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used." | CVSS3: 2.5 | 0% Низкий | около 1 года назад | |
CVE-2025-8534 A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used." | CVSS3: 2.5 | 0% Низкий | около 1 года назад | |
CVE-2025-8534 libtiff tiff2ps tiff2ps.c PS_Lvl2page null pointer dereference | CVSS3: 2.5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-8534 A vulnerability classified as problematic was found in libtiff 4.6.0. ... | CVSS3: 2.5 | 0% Низкий | около 1 года назад | |
ALT-PU-2025-11954 ALT-PU-2025-11954: package `libtiff` update to version 4.7.1-alt1 | CVSS3: 8.8 | 12 месяцев назад | ||
GHSA-xgh3-993q-r2x8 A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used." | CVSS3: 2.5 | 0% Низкий | около 1 года назад | |
SUSE-SU-2025:03346-1 Security update for tiff | около 1 года назад | |||
SUSE-SU-2025:03345-1 Security update for tiff | около 1 года назад | |||
SUSE-SU-2025:03348-1 Security update for tiff | около 1 года назад | |||
openSUSE-SU-2025:20049-1 Security update for tiff | 10 месяцев назад |
Уязвимостей на страницу