Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4330

Опубликовано: 15 нояб. 2016
Источник: redhat
CVSS3: 8.6
CVSS2: 6.8
EPSS Низкий

Описание

In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.

Multiple heap overflows were found in HDF5. These issues could be used to gain code execution in any program that exposes the affected functions to untrusted input. While HDF5 is shipped as a dependency, no Red Hat products are known to expose these issues in any supported use case at this time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)hdf5Will not fix
Red Hat OpenShift Enterprise 2hdf5Will not fix
Red Hat OpenStack Platform 10 (Newton)hdf5Will not fix
Red Hat OpenStack Platform 11 (Ocata)hdf5Not affected
Red Hat OpenStack Platform 8 (Liberty)hdf5Will not fix
Red Hat OpenStack Platform 9 (Mitaka)hdf5Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1397701hdf5: H5T_ARRAY heap buffer overflow

EPSS

Процентиль: 63%
0.00442
Низкий

8.6 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 9 лет назад

In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.

CVSS3: 8.6
nvd
около 9 лет назад

In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.

CVSS3: 8.6
debian
около 9 лет назад

In the HDF5 1.8.16 library's failure to check if the number of dimensi ...

CVSS3: 8.6
github
больше 3 лет назад

In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.

EPSS

Процентиль: 63%
0.00442
Низкий

8.6 High

CVSS3

6.8 Medium

CVSS2