Double Free in GDAL - CVE-2019-17545
Published: November 10, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the OGRExpatRealloc() function in ogr/ogr_expat.cpp. A remote attacker can pass a large amount of data to the application (more than 10M), trigger double free error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Oracle Database Server
SUSE Linux
Opensuse
Fedora
mingw-gdal
mingw-cfitsio
How to mitigate CVE-2019-17545
mingw-gdal - addressed in versions 2.3.2-7.fc30, 2.3.2-14.fc31
mingw-cfitsio - update to 3.470-2.fc31