libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tifstrip.c and (2) tiftile.c, a different vulnerability than CVE-2004-0804.