CVE-2019-25050: Buffer Overflow
Published Jul 20, 2021
·Updated
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4getatt (called from nc4getatttc and ncgetatttext) and in uffdcleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
Affected Software
1 affected component
OSGeo gdal>=2.4.2<=3.0.4
Remediation
Patch Available
Patch Available
Event History
Jul 20, 2021
CVE Published
via MITRE·06:46 AM
Data Sourced
via MITRE·06:46 AM
Description
Frequently Asked Questions
1
What is CVE-2019-25050?
CVE-2019-25050 is a vulnerability in netCDF in GDAL versions 2.4.2 through 3.0.4.
2
What is the severity of CVE-2019-25050?
The severity of CVE-2019-25050 is high with a CVSS score of 7.8.
3
Which software is affected by CVE-2019-25050?
The affected software is GDAL with versions 2.4.2 through 3.0.4.
4
How does CVE-2019-25050 work?
CVE-2019-25050 is caused by stack-based buffer overflow in nc4_get_att and uffd_cleanup functions in netCDFDataset.
5
Is there a fix available for CVE-2019-25050?
Yes, a fix has been released for CVE-2019-25050. It is recommended to update to the latest version of GDAL.