
CVE-2017-9935 – Debian Security Advisory 4100-1
https://notcve.org/view.php?id=CVE-2017-9935
26 Jun 2017 — In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an invalid free in TIFFClose or t2p_free, memory corruption in t2p_readwrite_pdf_image, or a double free in t2p_free. Given these possibilities, it probably could cause arbitrary code execution. En LibTIFF 4.0.8, hay un buffer overflow basado en el heap en la funció... • http://bugzilla.maptools.org/show_bug.cgi?id=2704 • CWE-125: Out-of-bounds Read •

CVE-2017-9937 – Ubuntu Security Notice USN-5742-1
https://notcve.org/view.php?id=CVE-2017-9937
26 Jun 2017 — In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack. En LibTIFF 4.0.8, hay una fallo en la asignación de memoria en el archivo tif_jbig.c. Un documento TIFF manipulado puede resultar en la aborción que lleva a un ataque de denegación de servicio. It was discovered that JBIG-KIT incorrectly handled decoding certain large image files. • http://bugzilla.maptools.org/show_bug.cgi?id=2707 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-5316 – Gentoo Linux Security Advisory 201701-16
https://notcve.org/view.php?id=CVE-2016-5316
09 Jan 2017 — Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool. Lectura fuera de límites en la función PixarLogCleanup en tif_pixarlog.c en libtiff 4.0.6 y versiones anteriores permite a atacantes remotos bloquear la aplicación enviando una imagen TIFF manipulada a la herramienta rgb2ycbcr. It was discovered that LibTIFF incorrectly handled certain malformed images. If a ... • http://lists.opensuse.org/opensuse-updates/2016-07/msg00087.html • CWE-125: Out-of-bounds Read •

CVE-2016-5315 – Gentoo Linux Security Advisory 201701-16
https://notcve.org/view.php?id=CVE-2016-5315
09 Jan 2017 — The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image. La función setByteArray en tif_dir.c en libtiff 4.0.6 y versiones anteriores permite a atacantes remotos provocar una denegación de servicio (lectura fuera de límites) a través de una imagen tiff manipulada. It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a s... • http://www.debian.org/security/2017/dsa-3762 • CWE-125: Out-of-bounds Read •

CVE-2016-5102 – Gentoo Linux Security Advisory 201701-16
https://notcve.org/view.php?id=CVE-2016-5102
09 Jan 2017 — Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file. Desbordamiento de búfer en la función readgifimage de gif2tiff.c en la herramienta gif2tiff en LibTIFF 4.0.6 permite a atacantes remotos provocar una denegación de servicio (fallo de segmentación) a través de un archivo gif manipulado It was discovered that LibTIFF incorrectly handled certain malformed images. If a ... • http://bugzilla.maptools.org/show_bug.cgi?id=2552 • CWE-20: Improper Input Validation •

CVE-2016-5314 – Gentoo Linux Security Advisory 201701-16
https://notcve.org/view.php?id=CVE-2016-5314
09 Jan 2017 — Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr. Desbordamiento de búfer en la función PixarLogDecode en tif_pixarlog.c en LibTIFF, en versiones 4.0.6 y anteriores, permite que atacantes remotos provoquen una denegación de servicio (cierre inesper... • http://bugzilla.maptools.org/show_bug.cgi?id=2554 • CWE-787: Out-of-bounds Write •

CVE-2016-5318 – Gentoo Linux Security Advisory 201701-16
https://notcve.org/view.php?id=CVE-2016-5318
09 Jan 2017 — Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff. Desbordamiento de búfer basado en pila en la función _TIFFVGetField en libtiff 4.0.6 y versiones anteriores permite a atacantes remotos bloquear la aplicación a través de un tiff manipulado. It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a re... • http://www.openwall.com/lists/oss-security/2016/04/27/6 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-5319 – Gentoo Linux Security Advisory 201701-16
https://notcve.org/view.php?id=CVE-2016-5319
09 Jan 2017 — Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file. Desbordamiento de búfer basado en memoria dinámica en tif_packbits.c en libtiff 4.0.6 y versiones anteriores permite a atacantes remotos bloquear la aplicación a través de un archivo bmp manipulado. Multiple vulnerabilities have been found in libTIFF, the worst of which may allow execution of arbitrary code. Versions less than 4.0.7 are affected. • http://www.openwall.com/lists/oss-security/2016/04/27/6 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-5321 – Gentoo Linux Security Advisory 201701-16
https://notcve.org/view.php?id=CVE-2016-5321
09 Jan 2017 — The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and crash) via a crafted tiff image. La función DumpModeDecode en libtiff 4.0.6 y versiones anteriores permite a atacantes provocar una denegación de servicio (lectura no válida y caída) a través de una imagen tiff manipulada. It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system were tricked into opening a specially crafted image, a remote... • http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00017.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-5323 – Gentoo Linux Security Advisory 201701-16
https://notcve.org/view.php?id=CVE-2016-5323
09 Jan 2017 — The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image. La función _TIFFFax3fillruns en libtiff en versiones anteriores a 4.0.6 permite a atacantes remotos provocar una denegación de servicio (error de división por cero y caída de aplicación) a través de una imagen Tiff manipulada. It was discovered that LibTIFF incorrectly handled certain malformed images. If a user or automated system... • http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00017.html • CWE-369: Divide By Zero •