- -------------------------------------------------------------------------
Debian Security Advisory DSA-5239-1                   security@debian.org
https://www.debian.org/security/                                  Aron Xu
September 27, 2022                    https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : gdal
CVE ID         : CVE-2021-45943

A heap-based buffer overflow vulnerability was discovered in gdal, a
Geospatial Data Abstraction Library, which could result in denial of
service or potentially the execution of arbitrary code, if a specially
crafted file is processed with the PCIDSK driver.

For the stable distribution (bullseye), this problem has been fixed in
version 3.2.2+dfsg-2+deb11u2.

We recommend that you upgrade your gdal packages.

For the detailed security status of gdal please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/gdal

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-5239-1: gdal security update

September 27, 2022
A heap-based buffer overflow vulnerability was discovered in gdal, a Geospatial Data Abstraction Library, which could result in denial of service or potentially the execution of ar...

Summary

For the stable distribution (bullseye), this problem has been fixed in
version 3.2.2+dfsg-2+deb11u2.

We recommend that you upgrade your gdal packages.

For the detailed security status of gdal please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/gdal

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Severity
A heap-based buffer overflow vulnerability was discovered in gdal, a
Geospatial Data Abstraction Library, which could result in denial of
service or potentially the execution of arbitrary code, if a specially
crafted file is processed with the PCIDSK driver.

Related News