There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
https://www.debian.org/security/2018/dsa-4100
https://usn.ubuntu.com/3602-1/
https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-5244