UbuntuUpdates.org

Package "libtiffxx6"

Name: libtiffxx6

Description:

Tag Image File Format (TIFF) library -- C++ interface

Latest version: 4.7.0-3ubuntu3.1
Release: questing (25.10)
Level: updates
Repository: main
Head package: tiff
Homepage: https://libtiff.gitlab.io/libtiff/

Links


Download "libtiffxx6"


Other versions of "libtiffxx6" in Questing

Repository Area Version
base main 4.7.0-3ubuntu3
security main 4.7.0-3ubuntu3.1

Changelog

Version: 4.7.0-3ubuntu3.1 2026-03-23 19:08:08 UTC

  tiff (4.7.0-3ubuntu3.1) questing-security; urgency=medium

  * SECURITY UPDATE: null-pointer dereference
    - debian/patches/CVE-2025-61143.patch: check for null pointer before call
      to TIFFFileName in tools/tiffcrop.c.
    - CVE-2025-61143
  * SECURITY UPDATE: stack buffer overflow
    - debian/patches/CVE-2025-61144.patch: update loop condition to also check
      samples against MAX_SAMPLES in tools/tiffcrop.c.
    - CVE-2025-61144

 -- Ian Constantin <email address hidden> Wed, 18 Mar 2026 10:40:57 +0200

CVE-2025-61143 libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
CVE-2025-61144 libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.



About   -   Send Feedback to @ubuntu_updates