UBUNTU-CVE-2021-45943
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-45943
Summary:
Details: GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
References: https://ubuntu.com/security/CVE-2021-45943, https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=41993, https://github.com/OSGeo/gdal/pull/4944, https://github.com/OSGeo/gdal/commit/93913a849dc1d217a40dbf9d6e6a3a23c42b61a6, https://github.com/OSGeo/gdal/commit/9b2bcbc47d1649adc0ab65b801f96f56156cf017, https://github.com/google/oss-fuzz-vulns/blob/main/vulns/gdal/OSV-2021-1651.yaml, https://github.com/OSGeo/gdal/commit/1ca6a3e5168c200763fa46d8aa7e698d0b757e7e, https://www.cve.org/CVERecord?id=CVE-2021-45943
Affected packages
Package
Name: gdal
Purl: pkg:deb/ubuntu/gdal?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
