Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wphc-7cm7-8mf7

Опубликовано: 27 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

Пакеты

Наименование

gdal

pip
Затронутые версииВерсия исправления

>= 3.1.0, < 3.13.1

3.13.1

EPSS

Процентиль: 1%
0.00102
Низкий

7.4 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

CVSS3: 7.4
nvd
3 месяца назад

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

CVSS3: 7.4
debian
3 месяца назад

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF ...

EPSS

Процентиль: 1%
0.00102
Низкий

7.4 High

CVSS3

Дефекты

CWE-121