Описание
Security update for hdf5
This update for hdf5 fixes the following issues:
- CVE-2021-46244: Fixed division by zero leading to DoS (bsc#1195215).
- CVE-2018-13867: Fixed out of bounds read in the function H5F__accum_read in H5Faccum.c (bsc#1101906).
- CVE-2018-16438: Fixed out of bounds read in H5L_extern_query at H5Lexternal.c (bsc#1107069).
- CVE-2020-10812: Fixed NULL pointer dereference (bsc#1167400).
- CVE-2021-45830: Fixed heap buffer overflow vulnerability in H5F_addr_decode_len in /hdf5/src/H5Fint.c (bsc#1194375).
- CVE-2019-8396: Fixed buffer overflow in function H5O__layout_encode in H5Olayout.c (bsc#1125882).
- CVE-2018-11205: Fixed out of bounds read was discovered in H5VM_memcpyvv in H5VM.c (bsc#1093663).
- CVE-2021-46242: Fixed heap-use-after free via the component H5AC_unpin_entry (bsc#1195212).
- CVE-2021-45833: Fixed stack buffer overflow vulnerability (bsc#1194366).
- CVE-2018-14031: Fixed heap-based buffer over-read in the function H5T_copy in H5T.c (bsc#1101475).
- CVE-2018-17439: Fixed out of bounds read in the function H5F__accum_read in H5Faccum.c (bsc#1111598).
Список пакетов
SUSE Linux Enterprise Module for HPC 15 SP4
SUSE Linux Enterprise Module for Package Hub 15 SP4
Ссылки
- Link for SUSE-SU-2022:3825-1
- E-Mail link for SUSE-SU-2022:3825-1
- SUSE Security Ratings
- SUSE Bug 1093663
- SUSE Bug 1101475
- SUSE Bug 1101906
- SUSE Bug 1107069
- SUSE Bug 1111598
- SUSE Bug 1125882
- SUSE Bug 1167400
- SUSE Bug 1194366
- SUSE Bug 1194375
- SUSE Bug 1195212
- SUSE Bug 1195215
- SUSE CVE CVE-2018-11205 page
- SUSE CVE CVE-2018-13867 page
- SUSE CVE CVE-2018-14031 page
- SUSE CVE CVE-2018-16438 page
- SUSE CVE CVE-2018-17439 page
- SUSE CVE CVE-2019-8396 page
Описание
A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
Затронутые продукты
Ссылки
- CVE-2018-11205
- SUSE Bug 1093663
Описание
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5F__accum_read in H5Faccum.c.
Затронутые продукты
Ссылки
- CVE-2018-13867
- SUSE Bug 1101906
Описание
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c.
Затронутые продукты
Ссылки
- CVE-2018-14031
- SUSE Bug 1101475
Описание
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.
Затронутые продукты
Ссылки
- CVE-2018-16438
- SUSE Bug 1107069
Описание
An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.
Затронутые продукты
Ссылки
- CVE-2018-17439
- SUSE Bug 1111598
Описание
A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while repacking an HDF5 file, aka "Invalid write of size 2."
Затронутые продукты
Ссылки
- CVE-2019-8396
- SUSE Bug 1125882
Описание
An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() located in H5Fquery.c. It allows an attacker to cause Denial of Service.
Затронутые продукты
Ссылки
- CVE-2020-10812
- SUSE Bug 1167400
Описание
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
Затронутые продукты
Ссылки
- CVE-2021-45830
- SUSE Bug 1194375
Описание
A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which causes a Denial of Service (context-dependent).
Затронутые продукты
Ссылки
- CVE-2021-45833
- SUSE Bug 1194366
Описание
HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
Затронутые продукты
Ссылки
- CVE-2021-46242
- SUSE Bug 1195212
Описание
A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability causes an aritmetic exception, leading to a Denial of Service (DoS).
Затронутые продукты
Ссылки
- CVE-2021-46244
- SUSE Bug 1195215