First published: Tue Jul 20 2021(Updated: )
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Osgeo Gdal | >=2.4.2<=3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-25050 is a vulnerability in netCDF in GDAL versions 2.4.2 through 3.0.4.
The severity of CVE-2019-25050 is high with a CVSS score of 7.8.
The affected software is GDAL with versions 2.4.2 through 3.0.4.
CVE-2019-25050 is caused by stack-based buffer overflow in nc4_get_att and uffd_cleanup functions in netCDFDataset.
Yes, a fix has been released for CVE-2019-25050. It is recommended to update to the latest version of GDAL.