CVE-2025-8851: LibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflow
A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8851?
CVE-2025-8851 is considered high severity due to the potential for stack-based buffer overflow leading to exploitation.
How do I fix CVE-2025-8851?
To fix CVE-2025-8851, upgrade LibTIFF to version 4.5.2 or later that addresses this vulnerability.
Who is affected by CVE-2025-8851?
CVE-2025-8851 affects users of LibTIFF tiffcrop version 4.5.1 and earlier.
What does CVE-2025-8851 exploit?
CVE-2025-8851 exploits a vulnerability in the readSeparateStripsetoBuffer function within the tiffcrop component.
Is local access required to exploit CVE-2025-8851?
Yes, local access is required to exploit CVE-2025-8851 due to the nature of the buffer overflow vulnerability.