libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
References
| Link | Resource |
|---|---|
| https://gist.github.com/optionGo/9c024cd8e7b131463b84dc60af9bb0aa | Third Party Advisory |
| https://gitlab.com/libtiff/libtiff/-/issues/737 | Issue Tracking |
| https://gitlab.com/libtiff/libtiff/-/merge_requests/755 | Issue Tracking |
Configurations
History
24 Feb 2026, 20:22
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* | |
| First Time |
Libtiff
Libtiff libtiff |
|
| References | () https://gist.github.com/optionGo/9c024cd8e7b131463b84dc60af9bb0aa - Third Party Advisory | |
| References | () https://gitlab.com/libtiff/libtiff/-/issues/737 - Issue Tracking | |
| References | () https://gitlab.com/libtiff/libtiff/-/merge_requests/755 - Issue Tracking | |
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CWE | CWE-476 |
23 Feb 2026, 19:22
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-23 19:22
Updated : 2026-02-25 15:20
NVD link : CVE-2025-61143
Mitre link : CVE-2025-61143
CVE.ORG link : CVE-2025-61143
JSON object : View
Products Affected
libtiff
- libtiff
CWE
CWE-476
NULL Pointer Dereference
