Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
"https://github.com/pypa/advisory-database/blob/main/vulns/exiv2/PYSEC-2018-143.yaml"