VYPR
Critical severity9.8NVD Advisory· Published Oct 14, 2019· Updated Jun 17, 2026

CVE-2019-17545

CVE-2019-17545

Description

GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

14
  • cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
  • cpe:2.3:a:oracle:spatial_and_graph:12.2.0.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:spatial_and_graph:12.2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:spatial_and_graph:19c:*:*:*:*:*:*:*
  • Osgeo/Gdal2 versions
    cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*range: <=3.0.1
    • (no CPE)range: <=3.0.1
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
  • GDAL/GDALdescription
  • osv-coords2 versions
    < 2.4.3-bp151.4.3.1+ 1 more
    • (no CPE)range: < 2.4.3-bp151.4.3.1
    • (no CPE)range: < 2.4.3-bp151.4.3.1

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.