Red Hat Bugzilla – Bug 1416109
CVE-2017-5563 libtiff: Heap-buffer overflow in LZWEncode tif_lzw.c
Last modified: 2017-01-26 05:33:57 EST
LibTIFF is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image. Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2664
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1410123]
Created mingw-libtiff tracking bugs for this issue: Affects: fedora-all [bug 1410124] Affects: epel-7 [bug 1410125]