UbuntuUpdates.org

Package "libtiff-tools"

Name: libtiff-tools

Description:

TIFF manipulation and conversion tools

Latest version: 4.7.0-3ubuntu3.1
Release: questing (25.10)
Level: security
Repository: universe
Head package: tiff
Homepage: https://libtiff.gitlab.io/libtiff/

Links


Download "libtiff-tools"


Other versions of "libtiff-tools" in Questing

Repository Area Version
base universe 4.7.0-3ubuntu3
updates universe 4.7.0-3ubuntu3.1

Changelog

Version: 4.7.0-3ubuntu3.1 2026-03-23 09:08:19 UTC

  tiff (4.7.0-3ubuntu3.1) questing-security; urgency=medium

  * SECURITY UPDATE: null-pointer dereference
    - debian/patches/CVE-2025-61143.patch: check for null pointer before call
      to TIFFFileName in tools/tiffcrop.c.
    - CVE-2025-61143
  * SECURITY UPDATE: stack buffer overflow
    - debian/patches/CVE-2025-61144.patch: update loop condition to also check
      samples against MAX_SAMPLES in tools/tiffcrop.c.
    - CVE-2025-61144

 -- Ian Constantin <email address hidden> Wed, 18 Mar 2026 10:40:57 +0200

CVE-2025-61143 libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
CVE-2025-61144 libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.



About   -   Send Feedback to @ubuntu_updates