VDB
BDU%3A2025-13921
BDU%3A2025-13921
PUBLISHED
CVSS 10 CRITICAL
Уязвимость библиотеки LibTIFF, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код на целевой системе
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», Silicon Graphics Corp. | Red Hat Enterprise Linux, openSUSE Tumbleweed, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, Альт 8 СП (запись в едином реестре российских программ №4305), SUSE Linux Enterprise Micro, SUSE Enterprise Storage, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, Astra Linux Common Edition (запись в едином реестре российских программ №4433), АЛЬТ СП 10, SUSE Liberty Linux, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Basesystem, SUSE Linux Enterprise Module for Package Hub, OpenSUSE Leap, SUSE Manager Proxy, SUSE Manager Retail Branch Server, SUSE Manager Server, LibTIFF |
Timeline
- Nov 10, 2025 CVE Published
- Feb 16, 2026 CVE Updated
References
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-libtiff-05112025/?sphrase_id=1339101 url
- https://github.com/SexyShoelessGodofWar/LibTiff-4.7.0-Write-What-Where?tab=readme-ov-file url
- https://security-tracker.debian.org/tracker/CVE-2025-9900 url
- https://access.redhat.com/security/cve/cve-2025-9900 url
- https://www.suse.com/ko-kr/security/cve/CVE-2025-9900.html url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-1113SE18 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-1202SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1216SE364 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20251225SE16 url
- https://wiki.astralinux.ru/astra-linux-se38-bulletin-2026-0126SE38 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1216SE47 advisory