In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.
{ "binaries": [ { "binary_version": "4.0.3-7ubuntu0.11+esm15", "binary_name": "libtiff-opengl" }, { "binary_version": "4.0.3-7ubuntu0.11+esm15", "binary_name": "libtiff-tools" }, { "binary_version": "4.0.3-7ubuntu0.11+esm15", "binary_name": "libtiff4-dev" }, { "binary_version": "4.0.3-7ubuntu0.11+esm15", "binary_name": "libtiff5" }, { "binary_version": "4.0.3-7ubuntu0.11+esm15", "binary_name": "libtiff5-alt-dev" }, { "binary_version": "4.0.3-7ubuntu0.11+esm15", "binary_name": "libtiff5-dev" }, { "binary_version": "4.0.3-7ubuntu0.11+esm15", "binary_name": "libtiffxx5" } ] }
{ "binaries": [ { "binary_version": "4.0.6-1ubuntu0.8+esm18", "binary_name": "libtiff-opengl" }, { "binary_version": "4.0.6-1ubuntu0.8+esm18", "binary_name": "libtiff-tools" }, { "binary_version": "4.0.6-1ubuntu0.8+esm18", "binary_name": "libtiff5" }, { "binary_version": "4.0.6-1ubuntu0.8+esm18", "binary_name": "libtiff5-dev" }, { "binary_version": "4.0.6-1ubuntu0.8+esm18", "binary_name": "libtiffxx5" } ] }