RHSA-2025:4658: Moderate: libtiff security update
Moderate: libtiff security update
Other sources
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.<br>Security Fix(es):<br><li> libtiff: Heap-based buffer overflow in tools/pal2rgb.c can lead to denial of service (CVE-2017-17095)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:4658?
The severity of RHSA-2025:4658 is classified as moderate.
How do I fix RHSA-2025:4658?
To fix RHSA-2025:4658, update the libtiff package to version 4.0.9-34.el8_10.
What vulnerability is addressed in RHSA-2025:4658?
RHSA-2025:4658 addresses a heap-based buffer overflow vulnerability in libtiff's pal2rgb tool (CVE-2017-17095).
Which systems are affected by RHSA-2025:4658?
RHSA-2025:4658 affects various versions of Red Hat Enterprise Linux and CodeReady Linux Builder across multiple architectures.
Is there a known exploit for RHSA-2025:4658?
While a specific exploit for CVE-2017-17095 has not been widely reported, the vulnerability can potentially lead to denial of service.