5.5

CVE-2021-45943

Exploit
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Osgeo ≫ Gdal Version >= 3.3.0 <= 3.4.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Oracle ≫ Spatial And Graph Version 19c
Oracle ≫ Spatial And Graph Version 21c
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.707
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.oracle.com/security-alerts/cpujul2022.html
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/01/msg00004.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2022/09/msg00040.html
Third Party Advisory
Mailing List
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=41993
Patch
Third Party Advisory
Exploit
Mailing List
Issue Tracking
https://github.com/OSGeo/gdal/commit/1ca6a3e5168c200763fa46d8aa7e698d0b757e7e
Patch
Third Party Advisory
https://github.com/OSGeo/gdal/pull/4944
Patch
Third Party Advisory
Exploit
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/gdal/OSV-2021-1651.yaml
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBPJGXY7IYY65NVJBLP3RONXE7ZBVCNU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P23E4DEHY5FJCR5VJ46I6TO32DT7Y3T4/
https://security.gentoo.org/glsa/202210-15
Third Party Advisory
https://www.debian.org/security/2022/dsa-5239
Third Party Advisory