An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
{
"binaries": [
{
"binary_name": "exiv2",
"binary_version": "0.28.5+dfsg-1"
},
{
"binary_name": "libexiv2-28",
"binary_version": "0.28.5+dfsg-1"
},
{
"binary_name": "libexiv2-data",
"binary_version": "0.28.5+dfsg-1"
},
{
"binary_name": "libexiv2-dev",
"binary_version": "0.28.5+dfsg-1"
}
]
}