Описание
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.
A flaw was found in the HDF5 library. A remote attacker could exploit a heap-based buffer overflow when processing specially crafted HDF5 files. This vulnerability, located in the H5G_ent_decode function, could lead to a denial of service or potentially allow for arbitrary code execution.
Отчет
This is a LOW impact heap-based buffer overflow in the HDF5 library. The flaw occurs when processing specially crafted HDF5 files, which could lead to a denial of service or potentially arbitrary code execution.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | hdf5 | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | hdf5 | Will not fix | ||
| Red Hat OpenStack Platform 10 (Newton) | hdf5 | Fix deferred | ||
| Red Hat OpenStack Platform 12 (Pike) | hdf5 | Affected | ||
| Red Hat OpenStack Platform 13 (Queens) | hdf5 | Fix deferred | ||
| Red Hat OpenStack Platform 14 (Rocky) | hdf5 | Fix deferred | ||
| Red Hat OpenStack Platform 8 (Liberty) | hdf5 | Will not fix | ||
| Red Hat OpenStack Platform 9 (Mitaka) | hdf5 | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.
An issue was discovered in the HDF HDF5 1.8.20 library. There is a hea ...
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer overflow in the function H5G_ent_decode in H5Gent.c.
EPSS
5.3 Medium
CVSS3