Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
栈缓冲区溢出
Vulnerability Title
GDAL 安全漏洞
Vulnerability Description
GDAL是GDAL开源的一款开源的地理空间数据抽象库。 GDAL 3.1.0版本至3.13.0版本存在安全漏洞,该漏洞源于netCDF驱动中scanForGeometryContainers函数将几何属性读入固定大小栈缓冲区时未验证属性长度,可能导致攻击者通过特制NetCDF文件嵌入超大几何属性实现栈缓冲区溢出,从而执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A