You need to log in before you can comment on or make changes to this bug.
Created an attachment (id=345) [details] test image for a code in Description In some cases PIXEL(buf,ix) macro reads memory at indices after buf's end. You can check this by running tiff2pdf with following command: tiff2pdf -o out.pdf tiger-minisblack-tile-01.tif (see attached image) At one point PIXEL will be called with ix==16 and buf==rp, so (ix)>>3 will evaluate in 2. At the same time refline (rp) has length == 2. So, PIXEL will read memory after refline's end.
Bugzilla is no longer used for tracking libtiff issues. Remaining open tickets, such as this one, have been migrated to the libtiff GitLab instance at https://gitlab.com/libtiff/libtiff/issues . The migrated tickets have their summary prefixed with [BZ#XXXX] where XXXX is the initial Bugzilla issue number.