An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/Exiv2/exiv2/issues/760 | third party advisory exploit |
https://security.gentoo.org/glsa/202312-06 | vendor advisory |