compat-libtiff3-3.9.4-14.el8_10
エラータID: AXSA:2025-10953:01
The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.
Security Fix(es):
* libtiff: Libtiff Write-What-Where (CVE-2025-9900)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2025-9900
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
Update packages.
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
N/A
SRPMS
- compat-libtiff3-3.9.4-14.el8_10.src.rpm
MD5: 471d040ce54da1f6344dc26824dcb13d
SHA-256: 4ce8563c78938758c65e766ba5889e9507862cc9493e0250a09c6dc6c827ca22
Size: 1.41 MB
Asianux Server 8 for x86_64
- compat-libtiff3-3.9.4-14.el8_10.i686.rpm
MD5: fd0968c891ff9322f08bfc4909132011
SHA-256: 5aea737e0643df50186d6751ea40e13a75e099e848e3a658c39fc5544fd438cb
Size: 149.94 kB - compat-libtiff3-3.9.4-14.el8_10.x86_64.rpm
MD5: 2aece6816d6a8792a052a65245a040fe
SHA-256: 04f8cb5d13c3ac128c9cec44a3bdf74f9944f9d088230206f92569ca01fc96df
Size: 142.60 kB