CVE-2025-61144

libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*

History

24 Feb 2026, 20:22

Type Values Removed Values Added
References () https://gist.github.com/optionGo/5ad17e96a0a40f03578dd6c9f8645952 - () https://gist.github.com/optionGo/5ad17e96a0a40f03578dd6c9f8645952 - Third Party Advisory
References () https://gitlab.com/libtiff/libtiff/-/commit/09f53a86cf26dfd961925227e59e180db617f26d - () https://gitlab.com/libtiff/libtiff/-/commit/09f53a86cf26dfd961925227e59e180db617f26d - Patch
References () https://gitlab.com/libtiff/libtiff/-/commit/88cf9dbb48f6e172629795ecffae35d5052f68aa - () https://gitlab.com/libtiff/libtiff/-/commit/88cf9dbb48f6e172629795ecffae35d5052f68aa - Patch
References () https://gitlab.com/libtiff/libtiff/-/issues/740 - () https://gitlab.com/libtiff/libtiff/-/issues/740 - Exploit, Issue Tracking
References () https://gitlab.com/libtiff/libtiff/-/merge_requests/757 - () https://gitlab.com/libtiff/libtiff/-/merge_requests/757 - Issue Tracking
First Time Libtiff
Libtiff libtiff
Summary
  • (es) Se descubrió que libtiff hasta la v4.7.1 contenía un desbordamiento de pila a través de la función readSeparateStripsIntoBuffer.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
CWE CWE-119
CPE cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*

23 Feb 2026, 19:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 19:22

Updated : 2026-02-25 15:20


NVD link : CVE-2025-61144

Mitre link : CVE-2025-61144

CVE.ORG link : CVE-2025-61144


JSON object : View

Products Affected

libtiff

  • libtiff
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer