CVE-2019-25050: OSGeo Gdal
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
Affected products
- OSGeo Gdal: from 2.4.2, up to and including 3.0.4
Published 2021-07-20. Last modified 2026-06-17.