Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-312

LibTIFF is vulnerable to an integer overflow

JLSEC Published
Modified
Affected Packages
Libtiff_jll < 4.6.0+0
Aliases / Upstream
CVE-2023-40745

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

References