CVE-2025-8961

A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.
References
Link Resource
http://www.libtiff.org/ Product
https://drive.google.com/file/d/15L4q2eD8GX3Aj3z6SWC3_FbqaM1ChUx2/view?usp=sharing Exploit
https://gitlab.com/libtiff/libtiff/-/issues/721 Exploit Issue Tracking Vendor Advisory
https://gitlab.com/libtiff/libtiff/-/issues/721#note_2670686960 Issue Tracking Exploit Vendor Advisory
https://vuldb.com/?ctiid.319955 Permissions Required VDB Entry
https://vuldb.com/?id.319955 Third Party Advisory VDB Entry
https://vuldb.com/?submit.627957 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:libtiff:libtiff:4.7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-14 13:15

Updated : 2025-09-11 17:00


NVD link : CVE-2025-8961

Mitre link : CVE-2025-8961

CVE.ORG link : CVE-2025-8961


JSON object : View

Products Affected

libtiff

  • libtiff
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer