Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-49014

Опубликовано: 27 мая 2026
Источник: debian
EPSS Низкий

Описание

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gdalfixed3.13.1+dfsg-1package
gdalno-dsatrixiepackage
gdalno-dsabookwormpackage

Примечания

  • https://github.com/OSGeo/gdal/issues/14594

  • https://github.com/OSGeo/gdal/pull/14598

  • Fixed by: https://github.com/OSGeo/gdal/commit/c49254dc6380af2f02ff43ca79e3cf7c1bc82f01

  • Fixed by: https://github.com/OSGeo/gdal/commit/50eea7456d83c9586f112ef96b43249372839dea (v3.13.1RC1)

EPSS

Процентиль: 1%
0.00102
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

CVSS3: 7.4
nvd
3 месяца назад

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

CVSS3: 7.4
github
3 месяца назад

GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow

EPSS

Процентиль: 1%
0.00102
Низкий