An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Upstream Issue: https://github.com/Exiv2/exiv2/issues/742
Created exiv2 tracking bugs for this issue: Affects: fedora-all [bug 2002673] Created mingw-exiv2 tracking bugs for this issue: Affects: fedora-all [bug 2002674]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-18899