Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66423.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-66423
Upstream
Published
2025-08-14T13:15:38Z
Modified
2026-04-01T05:20:57.753411Z
Summary
CVE-2025-8961 affecting package libtiff for versions less than 4.6.0-11
Details

A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.

References

Affected packages

Azure Linux:2 / libtiff

Package

Name
libtiff
Purl
pkg:rpm/azure-linux/libtiff

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.6.0-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66423.json"