CVE-2019-25050

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
20/07/2021
Last modified:
29/07/2021

Description

netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:* 2.4.2 (including) 3.0.4 (including)