The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade hdf5 | Dec 1, 2016 | Nov 18, 2016 |
| Freebsd | — | Upgrade hdf5Upgrade hdf5-18 | Jan 10, 2017 | Jan 9, 2017 |
| Gentoo Linux | — | Upgrade sci-libs/hdf5. | Oct 30, 2017 | Nov 18, 2016 |
| Suse | — | Upgrade hdf5-develUpgrade hdf5-openmpi-devel-staticUpgrade hdf5-openmpiUpgrade libhdf5-10-openmpiUpgrade libhdf5_hl10Upgrade libhdf5_fortran10-openmpiUpgrade hdf5-examplesUpgrade libhdf5-10Upgrade hdf5-devel-staticUpgrade libhdf5_fortran10Upgrade libhdf5_hl10-openmpiUpgrade libhdf5_cpp12Upgrade hdf5-devel-dataUpgrade libhdf5_hl_cpp11Upgrade hdf5Upgrade libhdf5hl_fortran10Upgrade hdf5-openmpi-develUpgrade libhdf5hl_fortran10-openmpi | Apr 24, 2018 | Nov 18, 2016 |
| Ubuntu | — | Upgrade hdf5 | Nov 19, 2024 | Nov 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub