When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade hdf5 | Dec 1, 2016 | Nov 18, 2016 |
| Freebsd | — | Upgrade hdf5-18Upgrade hdf5 | Jan 10, 2017 | Jan 9, 2017 |
| Gentoo Linux | — | Upgrade sci-libs/hdf5. | Oct 30, 2017 | Nov 18, 2016 |
| Suse | — | Upgrade libhdf5_hl10Upgrade hdf5Upgrade hdf5-devel-dataUpgrade hdf5-devel-staticUpgrade libhdf5-10-openmpiUpgrade libhdf5_cpp12Upgrade libhdf5-10Upgrade hdf5-examplesUpgrade hdf5-develUpgrade libhdf5_fortran10Upgrade hdf5-openmpiUpgrade libhdf5_hl10-openmpiUpgrade hdf5-openmpi-develUpgrade libhdf5_hl_cpp11Upgrade hdf5-openmpi-devel-staticUpgrade libhdf5hl_fortran10-openmpiUpgrade libhdf5hl_fortran10Upgrade libhdf5_fortran10-openmpi | Apr 25, 2018 | Nov 18, 2016 |
| Ubuntu | — | Upgrade hdf5 | Nov 19, 2024 | Nov 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub