The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly handle unknown tag types in TIFF directory entries, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF file.
No PoCs from references.
- https://github.com/mudongliang/LinuxFlaw
- https://github.com/oneoy/cve-