CVE-2021-45943: Buffer Overflow
Published Dec 31, 2021
·Updated
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
Affected Software
9 affected componentsFixes available
debian/gdal<=2.4.0+dfsg-1
2.4.0+dfsg-1+deb10u13.2.2+dfsg-2+deb11u23.6.2+dfsg-13.7.2+dfsg-1
OSGeo gdal>=3.3.0<=3.4.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Oracle Spatial And Graph=19c
Oracle Spatial And Graph=21c
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 1, 2022
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-45943.
2
What is the severity of CVE-2021-45943?
CVE-2021-45943 has a severity rating of medium with a CVSS score of 5.5.
3
What is the affected software?
The affected software includes GDAL versions 3.3.0 through 3.4.0.
4
How does the vulnerability manifest?
The vulnerability is a heap-based buffer overflow in the PCIDSK::CPCIDSKFile::ReadFromFile function.
5
How can I fix CVE-2021-45943?
To fix CVE-2021-45943, update GDAL to version 3.4.1 or higher.