The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file.
bb60000f6af9c141c2ef4116d6d57a18a2cf342fb2daab8cb8e5c99b583a5d0a