Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

CVE-2025-8177: rootio-tiff: Untrusted Tiff Image Can Crash Root Server

CVE-2025-8177 · published 11 days ago
Summary

The rootio-tiff package in Root:Debian:11 has a bug that can be exploited by an attacker to crash the server. This is a serious issue because it can cause the server to become unresponsive, potentially leading to downtime or data loss. To fix this issue, update to a patched version of the rootio-tiff package as soon as possible.

What to do
  • Update rootio-tiff to version 4.2.0-1+deb11u7.root.io.14.
  • Update rootio-tiff to version 4.2.0-1+deb11u7.root.io.13.
  • Update rootio-tiff to version 4.5.0-6+deb12u3.root.io.18.
  • Update rootio-tiff to version 4.5.0-6+deb12u4.root.io.19.
  • Update rootio-tiff to version 4.2.0-1+deb11u8.root.io.16.
  • Update debian tiff to version 4.7.1-1.
  • Update tiff to version 4.2.0-1+deb11u8.root.io.16.
  • Update tiff to version 4.5.0-6+deb12u4.aikido.21.
  • Update rootio-tiff to version 4.5.0-6+deb12u4.aikido.21.
  • Update tiff to version 4.5.0-6+deb12u4.aikido.22.
  • Update rootio-tiff to version 4.5.0-6+deb12u4.aikido.22.
Affected software
Ecosystem VendorProductAffected versions
Root:Debian:11 rootio-tiff < 4.2.0-1+deb11u7.root.io.14
< 4.2.0-1+deb11u7.root.io.13
< 4.2.0-1+deb11u8.root.io.16
Fix: upgrade to 4.2.0-1+deb11u7.root.io.14
Root:Debian:12 rootio-tiff < 4.5.0-6+deb12u3.root.io.18
< 4.5.0-6+deb12u4.root.io.19
< 4.5.0-6+deb12u4.aikido.21
< 4.5.0-6+deb12u4.aikido.22
Fix: upgrade to 4.5.0-6+deb12u3.root.io.18
Debian:11 debian tiff All versions
Debian:12 debian tiff All versions
Debian:13 debian tiff All versions
Debian:14 debian tiff < 4.7.1-1
Fix: upgrade to 4.7.1-1
Root:Debian:11 tiff < 4.2.0-1+deb11u8.root.io.16
Fix: upgrade to 4.2.0-1+deb11u8.root.io.16
Root:Debian:12 tiff < 4.5.0-6+deb12u4.aikido.21
< 4.5.0-6+deb12u4.aikido.22
Fix: upgrade to 4.5.0-6+deb12u4.aikido.21
Original advisory text
CVE-2025-8177 in tiff - Patched by Root
Root has patched CVE-2025-8177 in the tiff package for Root:Debian:11. Multiple fixed versions available.
Severity
6.9 Medium
CVSS 3.1: 7.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-119Buffer Overflow
CWE-120Classic Buffer Overflow
Timeline
Published23 Aug 2026
Updated3 Sep 2026
First seen30 Mar 2026
Monitor software like this
Free during beta