netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-07-20T06:46:38

Updated: 2024-08-05T03:00:18.922Z

Reserved: 2021-07-20T00:00:00

Link: CVE-2019-25050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-07-20T07:15:07.603

Modified: 2021-07-29T18:27:38.640

Link: CVE-2019-25050

cve-icon Redhat

No data.