An issue was discovered in LibTIFF 4.0.9. A buffer overflow can occur via an invalid or empty tif argument to TIFFWriteBufferSetup in tif_write.c, and it can be exploited (at a minimum) via the following high-level library API function: TIFFWriteTile. References: http://bugzilla.maptools.org/show_bug.cgi?id=2806
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1609419] Created mingw-libtiff tracking bugs for this issue: Affects: epel-7 [bug 1609420] Affects: fedora-all [bug 1609418]
CVE rejected.
Statement: Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.