Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-13872

Опубликовано: 10 июл. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.

A flaw was found in the HDF5 library. A remote attacker could exploit a heap-based buffer overflow when processing specially crafted HDF5 files. This vulnerability, located in the H5G_ent_decode function, could lead to a denial of service or potentially allow for arbitrary code execution.

Отчет

This is a LOW impact heap-based buffer overflow in the HDF5 library. The flaw occurs when processing specially crafted HDF5 files, which could lead to a denial of service or potentially arbitrary code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8hdf5Will not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)hdf5Will not fix
Red Hat OpenStack Platform 10 (Newton)hdf5Fix deferred
Red Hat OpenStack Platform 12 (Pike)hdf5Affected
Red Hat OpenStack Platform 13 (Queens)hdf5Fix deferred
Red Hat OpenStack Platform 14 (Rocky)hdf5Fix deferred
Red Hat OpenStack Platform 8 (Liberty)hdf5Will not fix
Red Hat OpenStack Platform 9 (Mitaka)hdf5Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1601480hdf5: HDF5 library: Arbitrary code execution or denial of service via specially crafted HDF5 files

EPSS

Процентиль: 78%
0.01853
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.

CVSS3: 9.8
nvd
около 8 лет назад

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.

CVSS3: 9.8
debian
около 8 лет назад

An issue was discovered in the HDF HDF5 1.8.20 library. There is a hea ...

CVSS3: 9.8
github
больше 4 лет назад

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.

EPSS

Процентиль: 78%
0.01853
Низкий

5.3 Medium

CVSS3