CVE-2017-12944 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12944): The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and application crash) in the TIFFFetchStripThing function in tif_dirread.c during a tiff2pdf invocation. References: http://bugzilla.maptools.org/show_bug.cgi?id=2725 Note: https://github.com/vadz/libtiff/commit/dc02f9050311a90b3c0655147cee09bfa7081cfc commit fixes the issue in TIFFFetchStripThing however the issue is still present in t2p_readwrite_pdf_image_tile.
This is already dealt with, at least SLOT 0 is clean. No idea about SLOT 3.
Package already cleaned from tree: Keywords for media-libs/tiff: commit ebfefcea | a | | | m | | | d x | | | 6 8 | | | 4 6 | u | | a a a p s | | | n | | l m r i p h m s p f m f | e u s | r | p d a m a p c x p 6 3 a b i b | a s l | e | h 6 r 6 6 p 6 8 p 8 9 s r s p s | p e o | p | a 4 m 4 4 c 4 6 a k 0 h c d s d | i d t | o ---------+---------------------------------+-------+------- 3.9.7-r1 | ~ + ~ + ~ ~ ~ + ~ + + + ~ o ~ ~ | 5 o 3 | gentoo ---------+---------------------------------+-------+------- 4.0.9-r4 | + + + + + + + + + + + + + ~ ~ ~ | 7 o 0 | gentoo
TIFFReadDirEntryArray() is not present in the 3.x code. Tree is secure.