VulnerabilityAnalyzed
CVE-2025-8961
A weakness has been identified in LibTIFF 4.7.0.
LOW 1.9EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.
- CVSS 4.0
- 1.9 LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- libtiff/libtiff
- Source
- cna@vuldb.com
References
- http://www.libtiff.org/Product
- https://drive.google.com/file/d/15L4q2eD8GX3Aj3z6SWC3_FbqaM1ChUx2/view?usp=sharingExploit
- https://gitlab.com/libtiff/libtiff/-/issues/721Exploit, Issue Tracking, Vendor Advisory
- https://gitlab.com/libtiff/libtiff/-/issues/721#note_2670686960Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.319955Permissions Required, VDB Entry
- https://vuldb.com/?id.319955Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.627957Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.