GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gdal | Nov 11, 2019 | Oct 14, 2019 |
| Oracle Missing Cpu Jul 2021 | — | Apply the July 2021 Critical Patch Update (CPU) for Oracle Database | Jul 21, 2021 | Oct 14, 2019 |
| Suse | — | Upgrade libgdal20Upgrade python3-GDALUpgrade gdalUpgrade python2-GDALUpgrade gdal-develUpgrade perl-gdal | Nov 12, 2019 | Oct 14, 2019 |
| Ubuntu | — | Upgrade gdal (Ubuntu Pro) | Nov 19, 2024 | Oct 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub