A flaw was found in Exiv2 0.26, there is an out-of-bounds read in Exiv2::IptcData::printStructure in image.cpp, a different vulnerability than CVE-2017-17724. It could result in denial of service or information disclosure. References: https://bugzilla.novell.com/show_bug.cgi?id=108789 https://github.com/Exiv2/exiv2/issues/254 https://github.com/xiaoqx/pocs/tree/master/exiv2
Created exiv2 tracking bugs for this issue: Affects: fedora-all [bug 1564279]
This CVE has been rejected by MITRE as a dup of CVE-2017-17724 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9146) *** This bug has been marked as a duplicate of bug 1545237 ***
Statement: This flaw was found to be a duplicate of CVE-2017-17724. Please see https://access.redhat.com/security/cve/CVE-2017-17724 for information about affected products and security errata.