Logo
vulnerabilityCVE-2025-8851
Name
CVE-2025-8851
Source
NVD ( link)Debian ( link)
Description
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
tiff
False Positive

Vulnerability Ratings#


4.8
CVSSv4
5.3
CVSSv31
4.3
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.7.1
Not Affected
buildroot
master
4.7.1
Not Affected
openwrt
master
4.7.1-r1
Not Affected
openwrt
openwrt-25.12
4.7.1-r1
Not Affected
yocto
kirkstone
4.3.0
Patched
yocto
master
4.7.1
Not Affected

Resolved with patches#


tiff (yocto:kirkstone)

#
Title
Author
Resolve
1
Attempt to address tiffcrop Coverity scan issues 1605444,
Lee Howard <faxguy@howardsilvan.com>
CVE-2025-8851