CVE
CVE-2017-10989
CVE ID |
CVE-2017-10989
|
---|---|
CVSS Score |
9.8
|
Operating System | |
Affected Versions |
CentOS 7
|
Patched Versions |
3.7.17-8_ol004.el7.1
|
Patch Date |
|
Additional Information
NVD Listing: https://nvd.nist.gov/vuln/detail/CVE-2017-10989
The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.