Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-8177

Published: July 29, 2025Last modified: August 6, 2025

Description

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

Severity score breakdown

ParameterValue
Base score5.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Notes

Crash in CLI tool, no security impact

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTStiffVulnerable (4.4.0-r1)
25 LTStiffVulnerable (4.7.0-r0)
StreamtiffVulnerable (4.4.0-r1)

References

ON THIS PAGE