CVE-2017-1000127 (NVD)

2017-11-17

Exiv2 0.26 contains a heap buffer overflow in tiff parser

Products Exiv2
Type Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)
First patch - None (likely due to unavailable code)
Links http://www.openwall.com/lists/oss-security/2017/06/30/1