netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4getatt (called from nc4getatttc and ncgetatttext) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
{
"binaries": [
{
"binary_name": "gdal-bin",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal-dev",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal-java",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal-perl",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal1-dev",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "libgdal1h",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "python-gdal",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
},
{
"binary_name": "python3-gdal",
"binary_version": "1.10.1+dfsg-5ubuntu1+esm1"
}
]
}
{
"binaries": [
{
"binary_name": "gdal-bin",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal-dev",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal-java",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal-perl",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal1-dev",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "libgdal1i",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "python-gdal",
"binary_version": "1.11.3+dfsg-3build2"
},
{
"binary_name": "python3-gdal",
"binary_version": "1.11.3+dfsg-3build2"
}
]
}
{
"binaries": [
{
"binary_name": "gdal-bin",
"binary_version": "2.2.3+dfsg-2"
},
{
"binary_name": "gdal-data",
"binary_version": "2.2.3+dfsg-2"
},
{
"binary_name": "libgdal-dev",
"binary_version": "2.2.3+dfsg-2"
},
{
"binary_name": "libgdal-java",
"binary_version": "2.2.3+dfsg-2"
},
{
"binary_name": "libgdal-perl",
"binary_version": "2.2.3+dfsg-2"
},
{
"binary_name": "libgdal20",
"binary_version": "2.2.3+dfsg-2"
},
{
"binary_name": "python-gdal",
"binary_version": "2.2.3+dfsg-2"
},
{
"binary_name": "python3-gdal",
"binary_version": "2.2.3+dfsg-2"
}
]
}