Executive brief
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
Affected products
- PyPI GDAL
Junglewise Threat Intelligence
CVE-2019-17545 · Severity: low · CVSS 3.1 · Published 2019-10-14
Technologies: GDAL (PyPI). Vendors: PyPI.
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.