216.73.216.31

CVE-2025-9900

· Published 23/09/2025 17:15 · Modified 24/09/2025 18:11

Labels: CVE-2025-9900 2025-09-23CVE-2025-9900CWE-123[email protected]

Essential information

Published
23/09/2025 17:15
Modified
24/09/2025 18:11
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
libtiff / libtiff cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*

References