CVE-2025-61143

EUVD-2025-207646
libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.66%
Affected Products (NVD)
VendorProductVersion
libtifflibtiff
𝑥
< 4.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tiff
bookworm
unimportant
bookworm (security)
unimportant
bullseye
unimportant
bullseye (security)
unimportant
forky
4.7.2-1
fixed
sid
4.7.2-1
fixed
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qtwebengine-opensource-src
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
texmaker
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
not-affected
xenial
not-affected
gdal
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
trusty
needs-triage
xenial
needs-triage
neuron
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
not-affected
questing
not-affected
resolute
not-affected
tiff
bionic
Fixed 4.0.9-5ubuntu0.10+esm10
released
focal
Fixed 4.1.0+git191117-2ubuntu0.20.04.14+esm3
released
jammy
Fixed 4.3.0-6ubuntu0.13
released
noble
Fixed 4.5.1+git230720-4ubuntu2.5
released
questing
Fixed 4.7.0-3ubuntu3.1
released
resolute
needed
trusty
Fixed 4.0.3-7ubuntu0.11+esm17
released
xenial
Fixed 4.0.6-1ubuntu0.8+esm20
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libtiff-devel
suse enterprise server 15 SP4
4.0.9-150000.45.63.1
fixed
libtiff5
suse enterprise desktop 15 SP7
4.0.9-150000.45.63.1
fixed
suse enterprise sap 15 SP7
4.0.9-150000.45.63.1
fixed
suse enterprise server 12 SP3
4.0.9-44.109.1
fixed
suse enterprise server 15 SP4
4.0.9-150000.45.63.1
fixed
suse enterprise server 15 SP7
4.0.9-150000.45.63.1
fixed
libtiff5-32bit
suse enterprise desktop 15 SP7
4.0.9-150000.45.63.1
fixed
suse enterprise sap 15 SP7
4.0.9-150000.45.63.1
fixed
suse enterprise server 12 SP3
4.0.9-44.109.1
fixed
suse enterprise server 15 SP4
4.0.9-150000.45.63.1
fixed
suse enterprise server 15 SP7
4.0.9-150000.45.63.1
fixed
tiff
suse enterprise server 12 SP3
4.0.9-44.109.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
compat-libtiff3
Amazon Linux 2
0:3.9.4-12.amzn2.0.8
fixed
compat-libtiff3-debuginfo
Amazon Linux 2
0:3.9.4-12.amzn2.0.8
fixed
libtiff
Amazon Linux 2
0:4.0.3-35.amzn2.0.29
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.25
fixed
libtiff-debuginfo
Amazon Linux 2
0:4.0.3-35.amzn2.0.29
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.25
fixed
libtiff-debugsource
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.25
fixed
libtiff-devel
Amazon Linux 2
0:4.0.3-35.amzn2.0.29
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.25
fixed
libtiff-static
Amazon Linux 2
0:4.0.3-35.amzn2.0.29
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.25
fixed
libtiff-tools
Amazon Linux 2
0:4.0.3-35.amzn2.0.29
fixed
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.25
fixed
libtiff-tools-debuginfo
Amazon Linux 2023
0:4.4.0-4.amzn2023.0.25
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
libtiff
Azure Linux 3.0
0:4.6.0-12.azl3
fixed
CBL-Mariner 2.0
0:4.6.0-12.cm2
fixed