In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack. Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2707
Created libtiff tracking bugs for this issue: Affects: fedora-all [bug 1469734] Created mingw-libtiff tracking bugs for this issue: Affects: epel-7 [bug 1469735] Affects: fedora-all [bug 1469736]
As per the upstream discussion, the vulnerability is in jbigkit, not libtiff.