{"id":"CVE-2025-9900","title":"A flaw was found in Libtiff","summary":"A flaw was found in Libtiff. This vulnerability is a \"write-what-where\" condition, triggered when the library processes a specially crafted TIFF image file.\n\nBy providing an abnormally large image height value in the file's metadata, an …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-123"],"published":"2025-09-23","updated":"2026-06-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-9900","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:17651","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:17675","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:17710","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:17738","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:17739","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:17740","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:19113","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:19156","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:19276","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:19906","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:19947","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:20956","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:20998","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21060","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21061","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21062","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21407","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21506","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21507","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21508","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21994","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23078","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23079","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23080","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:0001","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:0076","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:0077","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:0078","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:3461","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:3462","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:7504","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-9900","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2392784","label":"secalert@redhat.com"},{"url":"https://github.com/SexyShoelessGodofWar/LibTiff-4.7.0-Write-What-Where?tab=readme-ov-file","label":"secalert@redhat.com"},{"url":"https://gitlab.com/libtiff/libtiff/-/issues/704","label":"secalert@redhat.com"},{"url":"https://gitlab.com/libtiff/libtiff/-/merge_requests/732","label":"secalert@redhat.com"},{"url":"https://libtiff.gitlab.io/libtiff/releases/v4.7.1.html","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/26/3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00031.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/SexyShoelessGodofWar/LibTiff-4.7.0-Write-What-Where?tab=readme-ov-file","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00792,"epssPercentile":0.54356,"ingestedAt":"2026-06-29T13:24:34.572Z","slug":"CVE-2025-9900","body":"## Overview\n\nA flaw was found in Libtiff. This vulnerability is a \"write-what-where\" condition, triggered when the library processes a specially crafted TIFF image file.\n\nBy providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}