{"id":"CVE-2025-8851","summary":"LibTIFF tiffcrop tiffcrop.c readSeparateStripsetoBuffer stack-based overflow","details":"A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.","modified":"2026-09-10T14:34:31.848932Z","published":"2025-08-11T13:32:08.843Z","related":["SUSE-SU-2025:3957-1","SUSE-SU-2025:3989-1","SUSE-SU-2026:22234-1","SUSE-SU-2026:22306-1","openSUSE-SU-2025:15556-1","openSUSE-SU-2025:15682-1","openSUSE-SU-2026:20995-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8851.json","cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-121"]},"references":[{"type":"WEB","url":"http://www.libtiff.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8851.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8851"},{"type":"ADVISORY","url":"https://vuldb.com/?id.319382"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.624604"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.319382"},{"type":"FIX","url":"https://gitlab.com/libtiff/libtiff/-/commit/8a7a48d7a645992ca83062b3a1873c951661e2b3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/libtiff/libtiff","events":[{"introduced":"0"},{"fixed":"8a7a48d7a645992ca83062b3a1873c951661e2b3"}],"database_specific":{"cpe":"cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.5.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["4.5.0","4.5.1","v4.6.0rc1","v4.5.1rc3","v4.5.1","v4.5.1rc2","v4.5.1rc1","v4.5.0rc3","v4.5.0","v4.5.0rc2","v4.4.0rc1","v4.4.0","v4.3.0rc1","v4.3.0","v4.2.0","v4.1.0","v4.0.10","v4.0.9","v4.0.8","v4.0.7","v4.0.6","v4.0.5","v4.0.4","v4.0.4beta","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v4.0.0beta7","v4.0.0alpha6","v4.0.0alpha5","v4.0.0alpha4","v4.0.0alpha","v3.8.2","v3.8.1","v3.8.0","v3.7.4","v3.7.3","v3.7.2","v3.7.1","v3.7.0","v3.7.0beta2","v3.7.0beta","v3.7.0alpha","v3.6.1","v3.6.0","v3.6.0beta2","v3.5.7","v3.5.5","v3.5.4","v3.5.3"],"database_specific":{"vanir_signatures_modified":"2026-09-10T14:34:31Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"125298522252730818421245691744552631017","length":3979},"id":"CVE-2025-8851-28bcd593","signature_type":"Function","signature_version":"v1","source":"https://gitlab.com/libtiff/libtiff@8a7a48d7a645992ca83062b3a1873c951661e2b3","target":{"file":"tools/tiffcrop.c","function":"readSeparateStripsIntoBuffer"}},{"deprecated":false,"digest":{"function_hash":"34022840763250157474568839397085064740","length":6924},"id":"CVE-2025-8851-3452ee39","signature_type":"Function","signature_version":"v1","source":"https://gitlab.com/libtiff/libtiff@8a7a48d7a645992ca83062b3a1873c951661e2b3","target":{"file":"tools/tiffcrop.c","function":"computeInputPixelOffsets"}},{"digest":{"line_hashes":["36454668606399299175254352562079297732","86593624022343917326464537104057332182","297816011729360198695957399470278816102","123861256728091389215896363249692244411","71546548977246555874571454000912003165","94270534225520452429230680293087787513","53691178128712445025392756347489050518","79977354643059646240846593326149536825","316069950000112904847962696635819942549","139935833162598263634426386551541950132","147554800457837394638369826680900780974","209794363378237830095653664224621081086","168178383345132606674997683275615763509","15171199821626497939431793220763544586","92829902071770722406479005335305883946","276141438418785306018475415495915166670","63487499956538644684707008804100484765","41288238668761617364167757964345005628","283471126993750564820383235345562369159","211905676596364823751247821756842415302","120661997554235405725421301863932165211","79884091891383752394662996787880551727","84885903517656229598501670325406677430"],"threshold":0.9},"id":"CVE-2025-8851-91eb4ae2","signature_type":"Line","signature_version":"v1","source":"https://gitlab.com/libtiff/libtiff@8a7a48d7a645992ca83062b3a1873c951661e2b3","target":{"file":"tools/tiffcrop.c"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"29294408729669865357160709214619444427","length":5283},"id":"CVE-2025-8851-97860ee1","signature_type":"Function","signature_version":"v1","source":"https://gitlab.com/libtiff/libtiff@8a7a48d7a645992ca83062b3a1873c951661e2b3","target":{"file":"tools/tiffcrop.c","function":"computeOutputPixelOffsets"}}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-8851.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}