In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade hdf5 | Dec 1, 2016 | Nov 18, 2016 |
| Freebsd | — | Upgrade hdf5-18Upgrade hdf5 | Jan 10, 2017 | Jan 9, 2017 |
| Gentoo Linux | — | Upgrade sci-libs/hdf5. | Oct 30, 2017 | Nov 18, 2016 |
| Suse | — | Upgrade hdf5-openmpi-devel-staticUpgrade hdf5-develUpgrade hdf5-openmpi-develUpgrade libhdf5hl_fortran10Upgrade libhdf5_fortran10Upgrade libhdf5_fortran10-openmpiUpgrade hdf5Upgrade libhdf5-10-openmpiUpgrade hdf5-examplesUpgrade libhdf5_hl10Upgrade libhdf5-10Upgrade hdf5-devel-staticUpgrade libhdf5hl_fortran10-openmpiUpgrade hdf5-devel-dataUpgrade libhdf5_hl10-openmpiUpgrade hdf5-openmpiUpgrade libhdf5_hl_cpp11Upgrade libhdf5_cpp12 | Apr 25, 2018 | Nov 18, 2016 |
| Ubuntu | — | Upgrade hdf5 | Nov 19, 2024 | Nov 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub