Rapid7

vulnerability

Ubuntu: USN-5272-1 (CVE-2018-17233): HDF5 vulnerabilities

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Sep 20, 2018
Added
Mar 22, 2023
Modified
Mar 27, 2026

Description

A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

Solutions

ubuntu-pro-upgrade-hdf5-helpersubuntu-pro-upgrade-hdf5-toolsubuntu-pro-upgrade-libhdf5-10ubuntu-pro-upgrade-libhdf5-100ubuntu-pro-upgrade-libhdf5-103ubuntu-pro-upgrade-libhdf5-7ubuntu-pro-upgrade-libhdf5-cpp-100ubuntu-pro-upgrade-libhdf5-cpp-103ubuntu-pro-upgrade-libhdf5-cpp-11ubuntu-pro-upgrade-libhdf5-javaubuntu-pro-upgrade-libhdf5-jniubuntu-pro-upgrade-libhdf5-mpich-10ubuntu-pro-upgrade-libhdf5-mpich-100ubuntu-pro-upgrade-libhdf5-mpich-103ubuntu-pro-upgrade-libhdf5-mpich2-7ubuntu-pro-upgrade-libhdf5-openmpi-10ubuntu-pro-upgrade-libhdf5-openmpi-100ubuntu-pro-upgrade-libhdf5-openmpi-103ubuntu-pro-upgrade-libhdf5-openmpi-7
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.