CVE-2025-8177 MEDIUM

CVE-2025-8177: LibTIFF thumbnail.c setrow buffer overflow

Vendor N/A
Product LibTIFF
Weakness CWE-120
Published July 26, 2025
Last update July 28, 2025

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

Key dates

02Disclosure timeline

July 26, 2025 CVE published
July 28, 2025 Record updated