CVE-2025-8177

Source
https://cve.org/CVERecord?id=CVE-2025-8177
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-8177.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-8177
Downstream
AZL (2)
BELL (1)
CGA (2)
CLSA (4)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (1)
MINI (1)
OESA (3)
openSUSE (2)
RHSA (1)
ROOT (3)
SUSE (7)
UBUNTU (1)
Related
Published
2025-07-26T04:02:07Z
Modified
2026-08-18T17:54:50Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
LibTIFF thumbnail.c setrow buffer overflow
Details

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-119",
        "CWE-120"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8177.json"
}
References

Affected packages

Git / gitlab.com/libtiff/libtiff

Affected ranges

Type
GIT
Repo
https://gitlab.com/libtiff/libtiff
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "4.7.0"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

4.*
4.0
4.1
4.2
4.3
4.4
4.5
4.6
4.7.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-8177.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "297780625197446333907723077312940831795",
                "270735107877385796218935091708520464452",
                "315055247066183815880568827534154164368",
                "329264990900716605034686252948964790648"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2025-8177-8059c902",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://gitlab.com/libtiff/libtiff@e8c9d6c616b19438695fd829e58ae4fde5bfbc22",
        "target":  {
            "file":  "tools/thumbnail.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "11530096224261753264118971993864683479",
            "length":  1013
        },
        "id":  "CVE-2025-8177-e319bec8",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://gitlab.com/libtiff/libtiff@e8c9d6c616b19438695fd829e58ae4fde5bfbc22",
        "target":  {
            "file":  "tools/thumbnail.c",
            "function":  "setrow"
        }
    }
]
vanir_signatures_modified
"2026-08-18T17:54:50Z"