In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.
{ "vanir_signatures": [ { "id": "CVE-2018-8905-3fbe4683", "signature_type": "Function", "target": { "file": "libtiff/tif_lzw.c", "function": "LZWDecodeCompat" }, "source": "https://gitlab.com/libtiff/libtiff@58a898cb4459055bb488ca815c23b880c242a27d", "digest": { "function_hash": "120825719578505321660184962155054746977", "length": 4134.0 }, "deprecated": false, "signature_version": "v1" }, { "id": "CVE-2018-8905-e4506fa1", "signature_type": "Line", "target": { "file": "libtiff/tif_lzw.c" }, "source": "https://gitlab.com/libtiff/libtiff@58a898cb4459055bb488ca815c23b880c242a27d", "digest": { "threshold": 0.9, "line_hashes": [ "177967733808906035883593633810155823881", "203737156195573976975904104044591611902", "167066477237446475925485410116217217762", "173059985397098238975525246124703618955", "99427663126675737957365031708259496074", "289243857886536227372722331896346644343", "10214055182485147416901345635429964874", "183337954797534262759069573818295556151", "139234947298997046072255456576489018581", "244051190731298221544905369957809947884", "94663415500484428692874645151769140260", "212093616533759937923555560260924140032", "35273233916047150958507687928769187078", "217767932149858445127393940380373206037" ] }, "deprecated": false, "signature_version": "v1" } ] }