LibTIFF has a signed integer overflow, which might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2650 Upstream patch: https://github.com/vadz/libtiff/commit/66e7bd59520996740e4df5495a830b42fae48bc4
Created mingw-libtiff tracking bugs for this issue: Affects: fedora-all [bug 1438465]
Created mingw-libtiff tracking bugs for this issue: Affects: epel-7 [bug 1438466]
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1441273]