tif_read.c in LibTIFF does not ensure that tif_rawdata is properly initialized, which might allow attackers to crash the application, or possibly obtain sensitive information from process memory via a crafted image. Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2651 Upstream patch: https://github.com/vadz/libtiff/commit/d60332057b9575ada4f264489582b13e30137be1
Created mingw-libtiff tracking bugs for this issue: Affects: fedora-all [bug 1438465]
Created mingw-libtiff tracking bugs for this issue: Affects: epel-7 [bug 1438466]
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1441273]