CVE-2017-10989: sqlite: Heap-buffer overflow in the getNodeSize function

Severity: Critical

CVSS Score: 9.8

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.