LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow local attackers to cause a denial of service (memory consumption) via crafted file.
References:
http://seclists.org/oss-sec/2017/q4/164
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1474373]
Created mingw-libtiff tracking bugs for this issue:
Affects: epel-7 [bug 1474372]
Affects: fedora-all [bug 1474374]