libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.
https://usn.ubuntu.com/4277-1/
https://sourceforge.net/p/libexif/bugs/130/
https://lists.debian.org/debian-lts-announce/2020/05/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html