A flaw was found in gdal. A Heap-buffer-overflow in NITFRasterBand::Unpack. References: https://bugs.gentoo.org/623028
Created gdal tracking bugs for this issue: Affects: epel-all [bug 1618546] Affects: fedora-all [bug 1618545]
Laura, can you confirm release 2.3.1 fixes this?
(In reply to Pavel Raiskup from comment #2) > Laura, can you confirm release 2.3.1 fixes this? No, It doesn't. The commit that fix this issue was done after version 2.3.1 bump. https://gitweb.gentoo.org/repo/gentoo.git/log/sci-libs/gdal I've removed the version from the description as it was wrong
But still, fixed in version says gdal 2.3.0-r2. FWIW, you cite Gentoo tracker (not an upstream repo).
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.