In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.
[
{
"digest": {
"line_hashes": [
"170525206296602907753093694529980120856",
"93616978339748417209337682716870640681",
"328218603771540590479012731783112254210",
"48204508027133948625903716595036586778",
"251094784319949832704584338830552714731",
"319057619089807967802340759689575388816",
"286040623549323053884688996042829849908",
"302096191070558911570553740345273925536",
"58071185955440375749750412030001186165",
"296453592249262199560223406644893299582"
],
"threshold": 0.9
},
"target": {
"file": "libtiff/tif_print.c"
},
"deprecated": false,
"id": "CVE-2017-18013-665f1527",
"signature_version": "v1",
"signature_type": "Line",
"source": "https://gitlab.com/libtiff/libtiff@c6f41df7b581402dfba3c19a1e3df4454c551a01"
},
{
"digest": {
"length": 13275.0,
"function_hash": "304641741661058657797947578454949689153"
},
"target": {
"file": "libtiff/tif_print.c",
"function": "TIFFPrintDirectory"
},
"deprecated": false,
"id": "CVE-2017-18013-ef96e06b",
"signature_version": "v1",
"signature_type": "Function",
"source": "https://gitlab.com/libtiff/libtiff@c6f41df7b581402dfba3c19a1e3df4454c551a01"
}
]