CVE-2025-43961
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Apr 21, 2025
Updated: May 8, 2025
CWE ID 125
Summary
CVE-2025-43961 is a new vulnerability affecting the LibRaw library before version 0.21.4. The issue lies within the metadata/tiff.cpp file, specifically in the Fujifilm 0xf00c tag parser. This parser experiences an out-of-bounds read, which could potentially allow an attacker to read sensitive data beyond the intended boundary. Exploitation of this vulnerability could lead to information disclosure, posing a risk to system security. Users are advised to upgrade to the latest version of LibRaw to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LibRaw
Affected Vendors
- Libraw