Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-49014

Опубликовано: 27 мая 2026
Источник: nvd
CVSS3: 7.4
CVSS3: 7.8
EPSS Низкий

Описание

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*
Версия от 3.1.0 (включая) до 3.13.0 (включая)

EPSS

Процентиль: 1%
0.00102
Низкий

7.4 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

CVSS3: 7.4
debian
3 месяца назад

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF ...

CVSS3: 7.4
github
3 месяца назад

GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow

EPSS

Процентиль: 1%
0.00102
Низкий

7.4 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-121