A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a Denial of Service and limited information disclosure. This issue affects libtiff versions 4.x. References: https://gitlab.com/libtiff/libtiff/-/issues/536 https://gitlab.com/libtiff/libtiff/-/issues/537
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 2185077] Created mingw-libtiff tracking bugs for this issue: Affects: fedora-all [bug 2185078]