CVE-2025-8177: LibTIFF thumbnail.c setrow buffer overflow
A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.
Other sources
LibTIFF thumbnail.c setrow buffer overflow
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LibTIFFto a version that resolves this vulnerability.Patch e8c9d6c616b19438695fd829e58ae4fde5bfbc22 - Compensating control
Approach the attack locally (vulnerability affects local attacks); restrict or isolate local access to the affected LibTIFF functionality (tools/thumbnail.c, function setrow).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8177?
CVE-2025-8177 has been rated as critical due to the potential for buffer overflow exploits.
How do I fix CVE-2025-8177?
To fix CVE-2025-8177, update LibTIFF to the latest version beyond 4.7.0 where the vulnerability has been addressed.
What component of LibTIFF is affected by CVE-2025-8177?
CVE-2025-8177 affects the function setrow in the file tools/thumbnail.c of LibTIFF.
Is exploiting CVE-2025-8177 possible remotely?
Exploiting CVE-2025-8177 must be approached locally, as the vulnerability does not allow for remote attacks.
What type of vulnerability is CVE-2025-8177 classified as?
CVE-2025-8177 is classified as a buffer overflow vulnerability.