Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
CVE-2025-8177: rootio-tiff: Untrusted Tiff Image Can Crash Root Server
CVE-2025-8177 · published 11 days ago
Summary
The rootio-tiff package in Root:Debian:11 has a bug that can be exploited by an attacker to crash the server. This is a serious issue because it can cause the server to become unresponsive, potentially leading to downtime or data loss. To fix this issue, update to a patched version of the rootio-tiff package as soon as possible.
What to do
- Update rootio-tiff to version 4.2.0-1+deb11u7.root.io.14.
- Update rootio-tiff to version 4.2.0-1+deb11u7.root.io.13.
- Update rootio-tiff to version 4.5.0-6+deb12u3.root.io.18.
- Update rootio-tiff to version 4.5.0-6+deb12u4.root.io.19.
- Update rootio-tiff to version 4.2.0-1+deb11u8.root.io.16.
- Update debian tiff to version 4.7.1-1.
- Update tiff to version 4.2.0-1+deb11u8.root.io.16.
- Update tiff to version 4.5.0-6+deb12u4.aikido.21.
- Update rootio-tiff to version 4.5.0-6+deb12u4.aikido.21.
- Update tiff to version 4.5.0-6+deb12u4.aikido.22.
- Update rootio-tiff to version 4.5.0-6+deb12u4.aikido.22.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Debian:11 | – | rootio-tiff |
< 4.2.0-1+deb11u7.root.io.14 < 4.2.0-1+deb11u7.root.io.13 < 4.2.0-1+deb11u8.root.io.16 Fix: upgrade to 4.2.0-1+deb11u7.root.io.14
|
| Root:Debian:12 | – | rootio-tiff |
< 4.5.0-6+deb12u3.root.io.18 < 4.5.0-6+deb12u4.root.io.19 < 4.5.0-6+deb12u4.aikido.21 < 4.5.0-6+deb12u4.aikido.22 Fix: upgrade to 4.5.0-6+deb12u3.root.io.18
|
| Debian:11 | debian | tiff | All versions |
| Debian:12 | debian | tiff | All versions |
| Debian:13 | debian | tiff | All versions |
| Debian:14 | debian | tiff |
< 4.7.1-1 Fix: upgrade to 4.7.1-1
|
| Root:Debian:11 | – | tiff |
< 4.2.0-1+deb11u8.root.io.16 Fix: upgrade to 4.2.0-1+deb11u8.root.io.16
|
| Root:Debian:12 | – | tiff |
< 4.5.0-6+deb12u4.aikido.21 < 4.5.0-6+deb12u4.aikido.22 Fix: upgrade to 4.5.0-6+deb12u4.aikido.21
|
Original advisory text
CVE-2025-8177 in tiff - Patched by Root
Root has patched CVE-2025-8177 in the tiff package for Root:Debian:11. Multiple fixed versions available.
References
- https://vuldb.com/?submit.621797 Vendor Advisory
- https://gitlab.com/libtiff/libtiff/-/issues/715 Third Party Advisory
- https://gitlab.com/libtiff/libtiff/-/commit/e8c9d6c616b19438695fd829e58ae4fde5bf... Patch
- http://www.libtiff.org/ URL
- https://vuldb.com/?id.317591 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-8177 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8177.j... Vendor Advisory
- https://vuldb.com/?ctiid.317591 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2025-8177 Vendor Advisory
- https://gitlab.com/libtiff/libtiff/-/merge_requests/737 Patch
Severity
6.9
Medium
CVSS 3.1: 7.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-119Buffer Overflow
CWE-120Classic Buffer Overflow
Timeline
Published23 Aug 2026
Updated3 Sep 2026
First seen30 Mar 2026
Monitor software like this
Free during beta