In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0x1c" case.
{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.26"
}
]
}