CVE-2025-8961Improper Restriction of Operations within the Bounds of a Memory Buffer in Libtiff

Severity
4.8MEDIUMNVD
EPSS
0.0%
top 89.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 14
Latest updateSep 29

Description

A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5libtiff/libtiff4.7.0
NVDlibtiff/libtiff4.7.0

🔴Vulnerability Details

4
OSV
tiff vulnerabilities2025-09-29
CVEList
LibTIFF tiffcrop tiffcrop.c main memory corruption2025-08-14
GHSA
GHSA-7vmv-3r46-2vxx: A vulnerability was identified in LibTIFF 42025-08-14
OSV
CVE-2025-8961: A weakness has been identified in LibTIFF 42025-08-14

📋Vendor Advisories

4
Ubuntu
LibTIFF vulnerabilities2025-09-29
Red Hat
libtiff: LibTIFF memory corruption2025-08-14
Microsoft
LibTIFF tiffcrop tiffcrop.c main memory corruption2025-08-12
Debian
CVE-2025-8961: tiff - A weakness has been identified in LibTIFF 4.7.0. This affects the function main ...2025