Hide Forgot
An integer overflow vulnerability was found in DECLAREreadFunc leading to heap buffer overflow in cpStripToTile triggered by running tiffcp on crafted file. Upstream patch: https://github.com/vadz/libtiff/commit/787c0ee906430b772f33ca50b97b8b5ca070faec Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2610 CVE assignment: http://seclists.org/oss-sec/2017/q1/9
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1410123]
Created mingw-libtiff tracking bugs for this issue: Affects: fedora-all [bug 1410124] Affects: epel-7 [bug 1410125]