Описание
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
Отчет
In Red Hat OpenStack Platform 16 the hdf5 package is not actually utilized. Red Hat OpenStack Platform 13 will be retiring soon. For these reasons and because the flaw's impact is lower, no update will be provided at this time for the hdf5 package.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenStack Platform 13 (Queens) | hdf5 | Out of support scope | ||
Red Hat OpenStack Platform 16.1 | hdf5 | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via ...
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
Уязвимость функции H5F_addr_decode_len() в файле H5Fint.c. библиотеки HDF5, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.5 Medium
CVSS3