The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade hdf5 | Dec 1, 2016 | Nov 18, 2016 |
| Freebsd | — | Upgrade hdf5Upgrade hdf5-18 | Jan 10, 2017 | Jan 9, 2017 |
| Gentoo Linux | — | Upgrade sci-libs/hdf5. | Oct 30, 2017 | Nov 18, 2016 |
| Suse | — | Upgrade hdf5-devel-staticUpgrade libhdf5_fortran10-openmpiUpgrade libhdf5hl_fortran10-openmpiUpgrade hdf5-openmpi-devel-staticUpgrade libhdf5_hl10Upgrade hdf5-openmpiUpgrade hdf5-openmpi-develUpgrade libhdf5_cpp12Upgrade libhdf5_hl_cpp11Upgrade hdf5-devel-dataUpgrade hdf5-examplesUpgrade hdf5Upgrade libhdf5-10Upgrade libhdf5hl_fortran10Upgrade hdf5-develUpgrade libhdf5_fortran10Upgrade libhdf5_hl10-openmpiUpgrade libhdf5-10-openmpi | Apr 25, 2018 | Nov 18, 2016 |
| Ubuntu | — | Upgrade hdf5 | Nov 19, 2024 | Nov 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub