An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.25-2.1ubuntu16.04.3",
            "binary_name": "exiv2"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.3",
            "binary_name": "libexiv2-14"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.3",
            "binary_name": "libexiv2-dev"
        }
    ]
}
          {
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.25-3.1ubuntu0.18.04.2",
            "binary_name": "exiv2"
        },
        {
            "binary_version": "0.25-3.1ubuntu0.18.04.2",
            "binary_name": "libexiv2-14"
        },
        {
            "binary_version": "0.25-3.1ubuntu0.18.04.2",
            "binary_name": "libexiv2-dev"
        }
    ]
}