loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. https://gitlab.com/libtiff/libtiff/-/merge_requests/472
Created iv tracking bugs for this issue: Affects: fedora-all [bug 2215222] Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 2215223] Created mingw-libtiff tracking bugs for this issue: Affects: fedora-all [bug 2215224] Created tkimg tracking bugs for this issue: Affects: fedora-all [bug 2215226]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6575 https://access.redhat.com/errata/RHSA-2023:6575