ALT-PU-2020-1428-1
Closed vulnerabilities
BDU:2021-03591
Уязвимость компонента tif_getimage.c библиотеки LibTIFF, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-03342
Уязвимость функции OGRExpatRealloc файла ogr/ogr_expat.cpp. библиотеки-транслятора для геопространственных данных GDAL, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-17545
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
- openSUSE-SU-2019:2466
- openSUSE-SU-2019:2466
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16178
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16178
- https://github.com/OSGeo/gdal/commit/148115fcc40f1651a5d15fa34c9a8c528e7147bb
- https://github.com/OSGeo/gdal/commit/148115fcc40f1651a5d15fa34c9a8c528e7147bb
- [debian-lts-announce] 20191109 [SECURITY] [DLA 1984-1] gdal security update
- [debian-lts-announce] 20191109 [SECURITY] [DLA 1984-1] gdal security update
- [debian-lts-announce] 20220112 [SECURITY] [DLA 2877-1] gdal security update
- [debian-lts-announce] 20220112 [SECURITY] [DLA 2877-1] gdal security update
- [debian-lts-announce] 20220930 [SECURITY] [DLA 3129-1] gdal security update
- [debian-lts-announce] 20220930 [SECURITY] [DLA 3129-1] gdal security update
- FEDORA-2019-f511b38b1f
- FEDORA-2019-f511b38b1f
- FEDORA-2019-a6960910d8
- FEDORA-2019-a6960910d8
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html
Modified: 2024-11-21
CVE-2019-17546
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16443
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16443
- https://github.com/OSGeo/gdal/commit/21674033ee246f698887604c7af7ba1962a40ddf
- https://github.com/OSGeo/gdal/commit/21674033ee246f698887604c7af7ba1962a40ddf
- https://gitlab.com/libtiff/libtiff/commit/4bb584a35f87af42d6cf09d15e9ce8909a839145
- https://gitlab.com/libtiff/libtiff/commit/4bb584a35f87af42d6cf09d15e9ce8909a839145
- [debian-lts-announce] 20191126 [SECURITY] [DLA 2009-1] tiff security update
- [debian-lts-announce] 20191126 [SECURITY] [DLA 2009-1] tiff security update
- [debian-lts-announce] 20200318 [SECURITY] [DLA 2147-1] gdal security update
- [debian-lts-announce] 20200318 [SECURITY] [DLA 2147-1] gdal security update
- FEDORA-2020-2e9bd06377
- FEDORA-2020-2e9bd06377
- FEDORA-2020-6f1209bb45
- FEDORA-2020-6f1209bb45
- 20200121 [SECURITY] [DSA 4608-1] tiff security update
- 20200121 [SECURITY] [DSA 4608-1] tiff security update
- GLSA-202003-25
- GLSA-202003-25
- DSA-4608
- DSA-4608
- DSA-4670
- DSA-4670