In Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-8977.json"