A heap-buffer overflow vulnerability was found in libtiff. A maliciously crafted file could cause the application to crash. Upstream patch: https://github.com/vadz/libtiff/commit/9657bbe3cdce4aaa90e07d50c1c70ae52da0ba6a References: https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-heap-based-buffer-overflow/
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1438464] Created mingw-libtiff tracking bugs for this issue: Affects: epel-7 [bug 1438466] Affects: fedora-all [bug 1438465]