Red Hat Bugzilla – Bug 1531171
CVE-2017-18005 exiv2: null pointer dereference in the Exiv2::DataValue::toLong function in value.cpp
Last modified: 2018-04-30 18:17:56 EDT
Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a malformed TIFF file. The vulnerability causes a segmentation fault. [UPSTREAM BUG] https://github.com/Exiv2/exiv2/issues/168 [UPSTREAM PATCH] https://github.com/Exiv2/exiv2/pull/199