Re: CVE-2014-9330: Libtiff integer overflow in bmp2tiff

Posted by Michal Zalewski on Dec 22

It’s probably worth noting that although the bundled utilities are
pretty buggy, there are also several bugs affecting the libtiff
library itself that can be hit with afl if you clean up the
utility-level bugs first; these affect ImageMagick and any tools that
rely on libtiff to display untrusted images.

I reported some privately to the maintainers few weeks ago (before
your report, in fact), but haven’t had a lot of success so far….

Leave a Reply