RLSA-2025:17675

Source
https://errata.rockylinux.org/RLSA-2025:17675
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2025:17675.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2025:17675
Upstream
Published
2025-10-10T16:50:30.628847Z
Modified
2025-10-10T17:18:47.649316Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Important: compat-libtiff3 security update
Details

The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.

Security Fix(es):

  • libtiff: Libtiff Write-What-Where (CVE-2025-9900)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:8 / compat-libtiff3

Package

Name
compat-libtiff3
Purl
pkg:rpm/rocky-linux/compat-libtiff3?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:3.9.4-14.el8_10