GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
{ "cpes": [ "cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*" ], "severity": "Medium" }