Metrics
Affected Vendors & Products
Thu, 21 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Libtiff
Libtiff libtiff |
|
Vendors & Products |
Libtiff
Libtiff libtiff |
Wed, 20 Aug 2025 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 19 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 19 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. | |
Title | LibTIFF tiffcmp tiffcmp.c InitCCITTFax3 memory leak | |
Weaknesses | CWE-401 CWE-404 |
|
References |
|
|
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-19T20:02:13.694Z
Updated: 2025-08-19T20:31:44.305Z
Reserved: 2025-08-19T13:24:01.463Z
Link: CVE-2025-9165

Updated: 2025-08-19T20:31:40.032Z

Status : Awaiting Analysis
Published: 2025-08-19T20:15:37.557
Modified: 2025-08-20T14:40:17.713
Link: CVE-2025-9165
