Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11206

Опубликовано: 16 мая 2018
Источник: debian

Описание

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
hdf5fixed1.10.8+repack-1package
hdf5no-dsabullseyepackage
hdf5no-dsastretchpackage
hdf5no-dsajessiepackage
hdf5no-dsawheezypackage

Примечания

  • https://jira.hdfgroup.org/browse/HDFFV-10480

  • https://bitbucket.hdfgroup.org/projects/HDFFV/repos/hdf5/commits/992a199f90fec31e0ad72ed76ed279a3ccea59e4

  • https://github.com/TeamSeri0us/pocs/blob/master/hdf5/README2.md

  • Fixed in 1.10.x-series in 1.10.8 https://forum.hdfgroup.org/t/release-of-hdf5-1-10-8-newsletter-180/9108

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 3.3
redhat
больше 7 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 8.1
nvd
больше 7 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 8.1
github
больше 3 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 8.1
fstec
больше 7 лет назад

Уязвимость функций H5O_fill_new_decode, H5O_fill_old_decode компонента H5Ofill.c библиотеки обработки HDF файлов HDF5, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании