Buffer overflow in LibTIFF - CVE-2025-8177
Published: August 5, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the setrow() function in tools/thumbnail.c. A remote attacker can pass a specially crafted image to the application, trigger memory corruption and execute arbitrary code on the target system.
Affected software
SUSE Manager Proxy 4.3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.3
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Anolis OS
SUSE Enterprise Storage
Ubuntu
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Fedora
tiff (Ubuntu package)
libtiff
libtiff-devel
libtiff-static
libtiff-tools
libtiff (Red Hat package)
tiff
libtiff5-debuginfo
libtiff5
tiff-debuginfo
tiff-debugsource
libtiff5-32bit
libtiff5-debuginfo-32bit
libtiff5-32bit-debuginfo
libtiff-help
libtiff-debugsource
libtiff-debuginfo
libtiff6-64bit
libtiff6-64bit-debuginfo
libtiff-devel-64bit
libtiff-devel-docs
tiff-docs
libtiff6-debuginfo
libtiff6
libtiff6-32bit
libtiff-devel-32bit
libtiff6-32bit-debuginfo
How to mitigate CVE-2025-8177
libtiff - update to 4.0.3-35
libtiff-devel - update to 4.0.3-35
libtiff-static - update to 4.0.3-35
libtiff-tools - update to 4.0.3-35
libtiff (Red Hat package) - update to 4.0.3-35.el7_9.1
tiff - addressed in versions 4.0.9-44.89.1, 4.7.0-150600.3.13.1
libtiff5-debuginfo - addressed in versions 4.0.9-44.89.1, 4.0.9-150000.45.50.1
libtiff5 - addressed in versions 4.0.9-44.89.1, 4.0.9-150000.45.50.1
tiff-debuginfo - addressed in versions 4.0.9-44.89.1, 4.0.9-150000.45.50.1, 4.7.0-150600.3.13.1
tiff-debugsource - addressed in versions 4.0.9-44.89.1, 4.0.9-150000.45.50.1, 4.7.0-150600.3.13.1
libtiff5-32bit - addressed in versions 4.0.9-44.89.1, 4.0.9-150000.45.50.1
libtiff5-debuginfo-32bit - update to 4.0.9-44.89.1
libtiff-devel - addressed in versions 4.0.9-44.89.1, 4.0.9-150000.45.50.1, 4.7.0-150600.3.13.1
libtiff5-32bit-debuginfo - update to 4.0.9-150000.45.50.1
libtiff-help - addressed in versions 4.3.0-25, 4.3.0-39
libtiff-devel - addressed in versions 4.3.0-25, 4.3.0-39
libtiff-debugsource - addressed in versions 4.3.0-25, 4.3.0-39
libtiff-debuginfo - addressed in versions 4.3.0-25, 4.3.0-39
libtiff - addressed in versions 4.3.0-25, 4.3.0-39
libtiff-static - update to 4.3.0-39
libtiff-tools - update to 4.3.0-39
libtiff - addressed in versions 4.7.0-5.fc43, 4.7.0-6.fc42
libtiff6-64bit - update to 4.7.0-150600.3.13.1
libtiff6-64bit-debuginfo - update to 4.7.0-150600.3.13.1
libtiff-devel-64bit - update to 4.7.0-150600.3.13.1
libtiff-devel-docs - update to 4.7.0-150600.3.13.1
tiff-docs - update to 4.7.0-150600.3.13.1
libtiff6-debuginfo - update to 4.7.0-150600.3.13.1
libtiff6 - update to 4.7.0-150600.3.13.1
libtiff6-32bit - update to 4.7.0-150600.3.13.1
libtiff-devel-32bit - update to 4.7.0-150600.3.13.1
libtiff6-32bit-debuginfo - update to 4.7.0-150600.3.13.1
External References
Related Security Bulletins
- Multiple vulnerabilities in LibTIFF
- Fedora 43 update for libtiff
- Fedora 42 update for libtiff
- openEuler 22.03 LTS SP4 update for libtiff
- openEuler 22.03 LTS SP3 update for libtiff
- openEuler 20.03 LTS SP4 update for libtiff
- SUSE update for tiff
- SUSE update for tiff
- SUSE update for tiff
- SUSE update for tiff
- Ubuntu update for tiff
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for libtiff
- Anolis OS update for libtiff