LibTIFF has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image. Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2648 Upstream patch: https://github.com/vadz/libtiff/commit/0a76a8c765c7b8327c59646284fa78c3c27e5490
Created mingw-libtiff tracking bugs for this issue: Affects: fedora-all [bug 1438465]
Created mingw-libtiff tracking bugs for this issue: Affects: epel-7 [bug 1438466]
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1441273]