Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-17438

Опубликовано: 24 сент. 2018
Источник: debian
EPSS Низкий

Описание

A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
hdf5fixed1.10.6+repack-1package

Примечания

  • https://github.com/SegfaultMasters/covering360/tree/master/HDF5/vuln4#divided-by-zero---poc_h5d__select_io_h5dselect

  • https://jira.hdfgroup.org/browse/HDFFV-10587

  • fix in develop branch: https://bitbucket.hdfgroup.org/projects/HDFFV/repos/hdf5/commits/7add52ff4f2443357648d53d52add274d1b18b5f

  • Negligible security impact

EPSS

Процентиль: 69%
0.00605
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

CVSS3: 4.3
redhat
больше 7 лет назад

A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

CVSS3: 6.5
nvd
больше 7 лет назад

A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

CVSS3: 6.5
github
больше 3 лет назад

A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость компонента H5Dselect.c библиотеки обработки HDF файлов HDF5, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 69%
0.00605
Низкий