{"id":"OSV-2022-280","summary":"Heap-buffer-overflow in Exiv2::getULong","details":"OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=45993\n\n```\nCrash type: Heap-buffer-overflow READ 1\nCrash state:\nExiv2::getULong\nExiv2::Internal::isValidBoxFileType\nExiv2::Jp2Image::readMetadata\n```\n","modified":"2022-04-13T03:04:39.315882Z","published":"2022-03-26T00:00:34.484159Z","references":[{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=45993"}],"affected":[{"package":{"name":"exiv2","ecosystem":"OSS-Fuzz","purl":"pkg:generic/exiv2"},"ranges":[{"type":"GIT","repo":"https://github.com/Exiv2/exiv2","events":[{"introduced":"1545a1bc4aa4323ad15607d007918f3483c71dea"},{"fixed":"d16ca65b01188d28afbe5a52b1495ac0270dd95a"}]}],"ecosystem_specific":{"severity":"MEDIUM"},"database_specific":{"source":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/exiv2/OSV-2022-280.yaml"}}],"schema_version":"1.7.3"}