libtiff is plagued with many security problems, but upstream devs usually don't make releases when these problems are found and fixed. we've had to backport an obscene number of patches individually.

the current crop of security fixes do not apply cleanly without backporting a fair amount of unrelated changes. instead we just switch to building from the git master branch to get them all.

debian did the same:

(this same change would be applied to lib32-libtiff if accepted.)

