Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a malformed TIFF file. The vulnerability causes a segmentation fault. [UPSTREAM BUG] https://github.com/Exiv2/exiv2/issues/168 [UPSTREAM PATCH] https://github.com/Exiv2/exiv2/pull/199
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1577 https://access.redhat.com/errata/RHSA-2020:1577
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2017-18005