CVE-2021-45943
Summary
| CVE | CVE-2021-45943 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-01 01:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| PCIDSK: fix write heap-buffer-overflow. Fixes https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=41993 by rouault · Pull Request #4944 · OSGeo/gdal · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: gdal-3.2.2-3.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-fuzz-vulns/OSV-2021-1651.yaml at main · google/oss-fuzz-vulns · GitHub |
MISC |
github.com |
|
| Merge pull request #4944 from rouault/fix_ossfuzz_41993 · OSGeo/gdal@1ca6a3e · GitHub |
MISC |
github.com |
|
| [SECURITY] [DLA 2877-1] gdal security update |
MLIST |
lists.debian.org |
|
| 41993 -
oss-fuzz -
OSS-Fuzz: Fuzzing the planet -
Monorail |
MISC |
bugs.chromium.org |
|
| [SECURITY] Fedora 35 Update: mingw-gdal-3.3.3-3.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 3129-1] gdal security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 35 Update: mingw-gdal-3.3.3-3.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5239-1 gdal |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 34 Update: gdal-3.2.2-3.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| GDAL: Heap Buffer Overflow (GLSA 202210-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178998 Debian Security Update for gdal (DLA 2877-1)
- 181079 Debian Security Update for gdal (DSA 5239-1)
- 181087 Debian Security Update for gdal (DLA 3129-1)
- 182088 Debian Security Update for gdal (CVE-2021-45943)
- 20262 Oracle Database 21c Critical Patch Update - July 2022
- 20263 Oracle Database 19c Critical Patch Update - July 2022
- 20274 Oracle Database 19c Critical OJVM Patch Update - July 2022
- 282562 Fedora Security Update for gdal (FEDORA-2022-e85e37206b)
- 282564 Fedora Security Update for gdal (FEDORA-2022-cffca5dbf4)
- 710668 Gentoo Linux GDAL Heap Buffer Overflow Vulnerability (GLSA 202210-15)