An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/Exiv2/exiv2/issues/457 | third party advisory exploit |
https://access.redhat.com/errata/RHSA-2019:2101 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00009.html | vendor advisory |