GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
[
{
"id": "CVE-2019-17545-953d6849",
"target": {
"function": "OGRExpatRealloc",
"file": "gdal/ogr/ogr_expat.cpp"
},
"signature_version": "v1",
"digest": {
"length": 159.0,
"function_hash": "110395127982434165459425119816292298899"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/osgeo/gdal/commit/148115fcc40f1651a5d15fa34c9a8c528e7147bb"
},
{
"id": "CVE-2019-17545-bbef44bd",
"target": {
"file": "gdal/ogr/ogr_expat.cpp"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"308229990210759106968400908252313392300",
"152172563583615806696898864395479245553",
"259181652519837524019465353356666549752",
"91935301074849414130272711771149295592"
],
"threshold": 0.9
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/osgeo/gdal/commit/148115fcc40f1651a5d15fa34c9a8c528e7147bb"
}
]