Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.
| Software | From | Fixed in |
|---|---|---|
| libtiff / libtiff | 4.0.3 | 4.0.3.x |