Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/Exiv2/exiv2/issues/168 | issue tracking exploit third party advisory |
https://lists.debian.org/debian-lts-announce/2023/01/msg00004.html | third party advisory mailing list |