CVE-2019-17545
Summary
| CVE | CVE-2019-17545 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-14 02:15:00 UTC |
| Updated | 2023-11-07 03:06:00 UTC |
| Description | GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2877-1] gdal security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 30 Update: mingw-gdal-2.3.2-7.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: mingw-cfitsio-3.470-2.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| [security-announce] openSUSE-SU-2019:2466-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [SECURITY] [DLA 3129-1] gdal security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 31 Update: mingw-cfitsio-3.470-2.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 1984-1] gdal security update |
MLIST |
lists.debian.org |
|
| 16178 -
oss-fuzz -
OSS-Fuzz: Fuzzing the planet -
Monorail |
MISC |
bugs.chromium.org |
Third Party Advisory |
| [SECURITY] Fedora 30 Update: mingw-gdal-2.3.2-7.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| OGRExpatRealloc(): fix double-free when size to allocate is above the… · OSGeo/gdal@148115f · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178998 Debian Security Update for gdal (DLA 2877-1)
- 181087 Debian Security Update for gdal (DLA 3129-1)
- 20226 Oracle Database 19c Critical Patch Update - July 2021
- 20227 Oracle Database 12.2.0.1 Critical Patch Update - July 2021
- 20228 Oracle Database 12.2.0.1 Critical Patch Update - July 2021 (Unauthenticated)
- 20229 Oracle Database 12.1.0.2 Critical Patch Update - July 2021
- 20230 Oracle Database 12.1.0.2 Critical Patch Update - July 2021 (Unauthenticated)
- 20279 Oracle Database 19c Critical OJVM Patch Update - July 2021
- 20315 Oracle Database 12.2.0.1 Critical OJVM Patch Update - July 2021