CVE-2026-52491

EUVD-2026-66177
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.15%
Debian logo
Debian Releases
Debian Product
Codename
tiff
bookworm
unimportant
bookworm (security)
unimportant
forky
4.7.2-1
fixed
sid
4.7.2-1
fixed
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tiff
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
not-affected
trusty
not-affected
xenial
not-affected
qtwebengine-opensource-src
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
not-affected
texmaker
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
not-affected
xenial
not-affected
gdal
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
not-affected
trusty
not-affected
xenial
not-affected
neuron
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libtiff
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
libtiff-debuginfo
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
libtiff-devel
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
libtiff-static
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed
libtiff-tools
Amazon Linux 2
0:4.0.3-35.amzn2.0.32
fixed