The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.
| Software | From | Fixed in |
|---|---|---|
| libtiff / libtiff | - | 4.0.7 |
| opensuse / opensuse | 13.2 | 13.2.x |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |