Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-276

libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write

JLSEC Published
Modified
Affected Packages
Libtiff_jll < 4.4.0+0
Aliases / Upstream
CVE-2022-2867

libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation.

References