Medium severity5.5NVD Advisory· Published Jan 1, 2022· Updated Jun 17, 2026
CVE-2021-45943
CVE-2021-45943
Description
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:a:oracle:spatial_and_graph:19c:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:spatial_and_graph:19c:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:spatial_and_graph:21c:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- GDAL/GDALdescription
Patches
Vulnerability mechanics
References
11- github.com/OSGeo/gdal/commit/1ca6a3e5168c200763fa46d8aa7e698d0b757e7envdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party Advisory
- bugs.chromium.org/p/oss-fuzz/issues/detailnvdExploitIssue TrackingMailing ListPatchThird Party Advisory
- github.com/OSGeo/gdal/pull/4944nvdExploitPatchThird Party Advisory
- github.com/google/oss-fuzz-vulns/blob/main/vulns/gdal/OSV-2021-1651.yamlnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/01/msg00004.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/09/msg00040.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202210-15nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5239nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBPJGXY7IYY65NVJBLP3RONXE7ZBVCNU/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P23E4DEHY5FJCR5VJ46I6TO32DT7Y3T4/nvd
News mentions
0No linked articles in our index yet.