漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OSGeo gdal SWapi.c SWSDfldsrch heap-based overflow
Vulnerability Description
A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been published and may be used. Upgrading to version 3.13.0RC1 addresses this issue. This patch is called 3e04c0385630e4d42517046d9a4967dfccfeb7fd. The affected component should be upgraded.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
OSGeo gdal 缓冲区错误漏洞
Vulnerability Description
OSGeo gdal是OSGeo开源的一个地理空间栅格与矢量数据处理库。 OSGeo gdal 3.13.0dev-4及之前版本存在缓冲区错误漏洞,该漏洞源于文件frmts/hdf4/hdf-eos/SWapi.c中函数SWSDfldsrch,可能导致堆缓冲区溢出。
CVSS Information
N/A
Vulnerability Type
N/A