CVE-2025-8851

Public on 2025-08-11
Modified on 2025-08-15
Description
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core compat-libtiff3 2025-09-04 ALAS2-2025-2986 Fixed
Amazon Linux 1 libtiff No Fix Planned
Amazon Linux 2 - Core libtiff Pending Fix
Amazon Linux 2023 libtiff 2025-09-08 ALAS2023-2025-1164 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NVD CVSSv3 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NVD CVSSv2 4.3 AV:L/AC:L/Au:S/C:P/I:P/A:P