From ${URL} : http://bugzilla.maptools.org/show_bug.cgi?id=2508 > 2015-12-27 Even Rouault <even.rouault at spatialys.com> > > * libtiff/tif_next.c: fix potential out-of-bound write in NeXTDecode() > triggered by http://lcamtuf.coredump.cx/afl/vulns/libtiff5.tif > (bugzilla #2508) Fixing commit: https://github.com/vadz/libtiff/commit/b18012dae552f85dcc5c57d3bf4e997a15b1cc1c @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
CVE-2015-8784 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8784): The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif.
Patch is not present in the 4.0.6 sources. @maintainer(s), please patch as it does not look like upstream is releasing an update anytime soon.
Added to existing GLSA request.
This issue was resolved and addressed in GLSA 201701-16 at https://security.gentoo.org/glsa/201701-16 by GLSA coordinator Thomas Deutschmann (whissi).