libtiff-4.0.3-35.0.6.el7.AXS7
エラータID: AXSA:2025-11106:08
The libtiff package contains a library of functions for manipulating
TIFF (Tagged Image File Format) image format files. TIFF is a widely
used file format for bitmapped images. TIFF files usually end in the
.tif extension and they are often quite large.
The libtiff package should be installed if you need to manipulate TIFF
format image files.
Security Fix(es):
* CVE-2025-9900: fix write-what-where vulnerability in processing TIFF image
files
CVE(s):
CVE-2025-9900
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
Update packages.
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.
N/A
Asianux Server 7 for x86_64
- libtiff-4.0.3-35.0.6.el7.AXS7.i686.rpm
MD5: 2918591f61441c6d6c144073832d9d10
SHA-256: 1971d022d592309bda4d185db4d113a329a4a871709357946b54052b6716bb93
Size: 176.68 kB - libtiff-4.0.3-35.0.6.el7.AXS7.x86_64.rpm
MD5: 56cd6182aaec99017e8d70ca442ad04f
SHA-256: f29080703d36e9bc8ee5d288dd5b29d1bff9f82aeb80e110eb4d9682927dcf9f
Size: 173.81 kB - libtiff-devel-4.0.3-35.0.6.el7.AXS7.i686.rpm
MD5: 99724e4250bc7ca233d08a9a6ba574af
SHA-256: d51d2ce916bc7f6fbcc4ee5a238d86ad7c59c272a6db056faa25c585022d74a3
Size: 475.22 kB - libtiff-devel-4.0.3-35.0.6.el7.AXS7.x86_64.rpm
MD5: d82481171aa1f80248c6105d593c03ed
SHA-256: fb6d8200fa490594671e4b01130934669478237f28674b69a8d3485a092c036a
Size: 475.19 kB