Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.
https://usn.ubuntu.com/3606-1/
https://security.gentoo.org/glsa/201701-16
http://www.securityfocus.com/bid/88604