CVE-2017-17722 (https://nvd.nist.gov/vuln/detail/CVE-2017-17722): In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remote denial of service attack via a crafted TIFF file.
It would really help if these NVDs would link to *actual* upstream bugs.
bigtiffimage.cpp does not even exist in 0.26 branch, so this is a bogus report. Affected is only master, that we don't provide, and which is fixed upstream already.
Does not apply to us as Andreas mentioned.