CVE-2019-17545Double Free in Gdal

CWE-415Double Free10 documents7 sources
Severity
9.8CRITICALNVD
EPSS
2.2%
top 15.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateMay 24

Description

GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Debianosgeo/gdal< 2.4.2+dfsg-2+3
NVDosgeo/gdal3.0.1
NVDopensuse/leap15.1
NVDoracle/spatial_and_graph12.2.0.1, 19c+1

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 30, 31

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f6m2-5v5j-rhf2: GDAL through 32022-05-24
OSV
CVE-2019-17545: GDAL through 32019-10-14
CVEList
CVE-2019-17545: GDAL through 32019-10-14

📋Vendor Advisories

2
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph (GDAL) — CVE-2019-175452021-07-15
Debian
CVE-2019-17545: gdal - GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_e...2019

💬Community

4
Bugzilla
CVE-2019-17545 gdal: double free in OGRExpatRealloc in ogr/ogr_expat.cpp [epel-all]2019-10-25
Bugzilla
CVE-2019-17545 mingw-gdal: gdal: double free in OGRExpatRealloc in ogr/ogr_expat.cpp [fedora-all]2019-10-25
Bugzilla
CVE-2019-17545 gdal: double free in OGRExpatRealloc in ogr/ogr_expat.cpp2019-10-25
Bugzilla
CVE-2019-17545 gdal: double free in OGRExpatRealloc in ogr/ogr_expat.cpp [fedora-all]2019-10-25
CVE-2019-17545 — Double Free in Osgeo Gdal | cvebase