{"id":"AZL-65970","summary":"CVE-2025-8177 affecting package libtiff for versions less than 4.6.0-7","details":"A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.","modified":"2026-04-01T05:20:40.328528Z","published":"2025-07-26T04:16:10Z","upstream":["CVE-2025-8177"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8177"}],"affected":[{"package":{"name":"libtiff","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libtiff"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.0-7"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-65970.json"}}],"schema_version":"1.7.5"}