Описание
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
hdf5 | fixed | 1.14.5+repack-1 | package |
Примечания
https://github.com/HDFGroup/hdf5/issues/1329
https://github.com/advisories/GHSA-x9pw-hh7v-wjpf
https://github.com/HDFGroup/hdf5/pull/2255
https://github.com/HDFGroup/hdf5/commit/24700e8f0607e9a3782c843528e2c5a892d4d6f6
Negligible security impact, malicous scientific data has more issues than a crash...
EPSS
Связанные уязвимости
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
Уязвимость компонента H5AC_unpin_entry библиотеки HDF5, позволяющая нарушителю оказывать влияние на конфиденциальность, целостность и доступность информации
EPSS