OSGeo gdal
cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*
- < 3.11.0
This vulnerability is being actively exploited in the wild.
A vulnerability has been identified in OSGeo GDAL versions prior to 3.11.0, specifically within the Zlib module's contribution 'infback9'. This issue involves improper restriction of operations within the bounds of a memory buffer, potentially leading to memory-related vulnerabilities.
Exploitation of this vulnerability could lead to memory corruption issues, commonly associated with buffer overflow vulnerabilities, which may allow for arbitrary code execution or causing a denial-of-service condition.
Users can upgrade to OSGeo GDAL version 3.11.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.