CVE-2019-25050
HIGH7.8EPSS 0.09%發布日:2021/7/20修改日:2026/4/28
也稱為:DEBIAN-CVE-2019-25050
描述
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
受影響套件(2)
- Debian/gdalfrom 0, < 3.1.0+dfsg-1
- PyPI/gdalfrom 0, < 767e3a56144f676ca738ef8f700e0e56035bd05a, < 27b9bf644bcf1208f7d6594bdd104cc8a8bb0646 | >= 2.4.2, < 3.1.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
參考連結(7)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2019-25050
- PATCHhttps://github.com/OSGeo/gdal/commit/27b9bf644bcf1208f7d6594bdd104cc8a8bb0646
- PATCHhttps://github.com/OSGeo/gdal/commit/767e3a56144f676ca738ef8f700e0e56035bd05a
- WEBhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15143
- WEBhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15156
- WEBhttps://github.com/google/oss-fuzz-vulns/blob/main/vulns/gdal/OSV-2020-392.yaml
- WEBhttps://github.com/google/oss-fuzz-vulns/blob/main/vulns/gdal/OSV-2020-420.yaml