[CLSA-2025:1758823373] libtiff: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-09-25 18:03:00 UTC
Description:
- CVE-2025-8176: fix use after free vulnerability in get_histogram function that prevents proper scanline reading and processing in tools/tiffmedian.c - CVE-2025-8177: fix array overflow in thumbnail generation that could cause buffer overflow when processing malformed TIFF files in tools/thumbnail.c
Updated packages:
  • libtiff-4.4.0-8.el9_2.tuxcare.els5.i686.rpm
    sha:7b5d40f6da94b2174046c9cb30a7597a3b125ef01ca440b6625f46b17ceee52b
  • libtiff-4.4.0-8.el9_2.tuxcare.els5.x86_64.rpm
    sha:4b5493b50cc0e7f49c0275abd52fd7bf727c6f3b5466083fff2cbccec5942e92
  • libtiff-devel-4.4.0-8.el9_2.tuxcare.els5.i686.rpm
    sha:b6f858744feb3b5e2fca41adff8dc91bb609c9ddf0cb6fcfde8831e28a2a4cff
  • libtiff-devel-4.4.0-8.el9_2.tuxcare.els5.x86_64.rpm
    sha:476821ef9fcd09c6e8f54b471981dd2f378cffc60eea31dd792ef2daf28af9c6
  • libtiff-static-4.4.0-8.el9_2.tuxcare.els5.x86_64.rpm
    sha:84219491fef450f5e5716bd46e6bf12cd27242858be9b66d60e214996188414d
  • libtiff-tools-4.4.0-8.el9_2.tuxcare.els5.x86_64.rpm
    sha:22407bd2ab4afd0b49612da2a3616985e36e750d49b844fbce9905803166f457
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.