Red Hat Bugzilla – Bug 1635091
CVE-2018-17795 libtiff: Heap-based buffer overflow in tiff2pdf.c:t2p_write_pdf()
Last modified: 2018-10-18 13:57:25 EDT
The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935. Upstream Bug: http://bugzilla.maptools.org/show_bug.cgi?id=2816
Not reproducible on f28 with libtiff-tools-4.0.9-10.fc28.x86_64.
Unable to reproduce on any RHEL* packages.