CVE-2025-61144
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aReferences
https://gist.github.com/optionGo/5ad17e96a0a40f03578dd6c9f8645952https://gitlab.com/libtiff/libtiff/-/commit/09f53a86cf26dfd961925227e59e180db617f26dhttps://gitlab.com/libtiff/libtiff/-/commit/88cf9dbb48f6e172629795ecffae35d5052f68aahttps://gitlab.com/libtiff/libtiff/-/issues/740https://gitlab.com/libtiff/libtiff/-/merge_requests/757