NULL Pointer Dereference in libtiff Affects Multiple Versions
CVE-2025-61143

5.5MEDIUM

Key Information:

Vendor

libtiff

Status
Vendor
CVE Published:
23 February 2026

What is CVE-2025-61143?

A NULL pointer dereference has been identified in libtiff, present in versions up to v4.7.1. This vulnerability occurs in the component libtiff/tif_open.c, which could lead to potential crashes or system instability when the affected product is used improperly. It is crucial for users and administrators to apply necessary updates or mitigation strategies to safeguard their systems from possible exploitation.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.