CLSA-2025-1745531344

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1745531344.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2025-1745531344
Upstream
Published
2025-04-24T21:49:09Z
Modified
2026-06-01T00:30:21.112158270Z
Summary
libtiff: Fix of 2 CVEs
Details
  • CVE-2023-40745: prevent integer overflow on hostile images to avoid heap-based buffer overflow and potential code execution
  • CVE-2023-41175: address integer overflows and bypass in raw2tiff.c to prevent heap-based buffer overflow and potential code execution
References

Affected packages

TuxCare:AlmaLinux:9.2 / libtiff

Package

Name
libtiff
Purl
pkg:rpm/tuxcare/libtiff?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.0-8.el9_2.tuxcare.els4

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1745531344.json"

TuxCare:AlmaLinux:9.2 / libtiff-devel

Package

Name
libtiff-devel
Purl
pkg:rpm/tuxcare/libtiff-devel?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.0-8.el9_2.tuxcare.els4

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1745531344.json"

TuxCare:AlmaLinux:9.2 / libtiff-static

Package

Name
libtiff-static
Purl
pkg:rpm/tuxcare/libtiff-static?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.0-8.el9_2.tuxcare.els4

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1745531344.json"

TuxCare:AlmaLinux:9.2 / libtiff-tools

Package

Name
libtiff-tools
Purl
pkg:rpm/tuxcare/libtiff-tools?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.0-8.el9_2.tuxcare.els4

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1745531344.json"