Description: An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB. Broken commit info: Bugfix commit info: https://gitlab.com/libtiff/libtiff/-/commit/5320c9d89c054fa805d037d84c57da874470b01a https://gitlab.com/libtiff/libtiff/-/merge_requests/545 https://gitlab.com/libtiff/libtiff/-/commit/abb4476fd2be87fc8ded3078e019f22f84ee0e8c https://gitlab.com/libtiff/libtiff/-/commit/4728ce9b8e28ef6ac4c518eab1cc94ad2e0d824e https://gitlab.com/libtiff/libtiff/-/commit/264a28eff71cf0038ba7b235238512fa594fa42f https://gitlab.com/libtiff/libtiff/-/commit/d6bbe53a96b031ab8b53d20241825ddf9e8bf8f1
PR: https://e.gitee.com/openanolis/repos/src-anolis-os/libtiff/pulls/21?tab=files