Re: CVE-2014-9330: Libtiff integer overflow in bmp2tiff

Posted by Paris Zoumpouloglou on Dec 22

It’s true utilities are pretty buggy. I’ve stumbled upon many duplicate
bugs in the tracker, probably because of all the afl action 🙂

What is also worth noting (I didn’t notice at first) is that the latest
available stable source code of libtiff (found here
http://download.osgeo.org/libtiff/) hasn’t been updated since 2012.

Since then many bugs have been reported which have been fixed in the CVS
repo and distribution…

Leave a Reply