Описание
Security update for hdf5
This update for hdf5 fixes the following issues:
- Fix bsc#1224158 - this fixes: CVE-2024-29158, CVE-2024-29161, CVE-2024-29166, CVE-2024-32608, CVE-2024-32610, CVE-2024-32614, CVE-2024-32619, CVE-2024-32620, CVE-2024-33873, CVE-2024-33874, CVE-2024-33875 Additionally, these fixes resolve crashes triggered by the reproducers for CVE-2017-17507, CVE-2018-11205. These crashes appear to be unrelated to the original problems.
This update also ships several missing PackageHub packages for 15 SP5 and 15 SP6.
Список пакетов
Image SLES15-SP3-HPC-BYOS-Azure
Image SLES15-SP3-HPC-BYOS-EC2-HVM
Image SLES15-SP3-HPC-BYOS-GCE
Image SLES15-SP4-HPC-BYOS
Image SLES15-SP4-HPC-BYOS-Azure
Image SLES15-SP4-HPC-BYOS-EC2
Image SLES15-SP4-HPC-BYOS-GCE
Image SLES15-SP4-HPC-EC2
Image SLES15-SP4-HPC-GCE
Image SLES15-SP5-HPC-Azure
Image SLES15-SP5-HPC-BYOS-Azure
Image SLES15-SP5-HPC-BYOS-EC2
Image SLES15-SP5-HPC-BYOS-GCE
Image SLES15-SP6-HPC
Image SLES15-SP6-HPC-Azure
Image SLES15-SP6-HPC-BYOS
Image SLES15-SP6-HPC-BYOS-Azure
Image SLES15-SP6-HPC-BYOS-EC2
Image SLES15-SP6-HPC-BYOS-GCE
Image SLES15-SP6-HPC-EC2
Image SLES15-SP6-HPC-GCE
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
SUSE Linux Enterprise Module for HPC 15 SP5
SUSE Linux Enterprise Module for HPC 15 SP6
SUSE Linux Enterprise Module for Package Hub 15 SP5
SUSE Linux Enterprise Module for Package Hub 15 SP6
SUSE Linux Enterprise Module for Server Applications 15 SP5
SUSE Linux Enterprise Module for Server Applications 15 SP6
openSUSE Leap 15.5
openSUSE Leap 15.6
Ссылки
- Link for SUSE-SU-2024:2195-1
- E-Mail link for SUSE-SU-2024:2195-1
- SUSE Security Ratings
- SUSE Bug 1224158
- SUSE CVE CVE-2017-17507 page
- SUSE CVE CVE-2018-11205 page
- SUSE CVE CVE-2024-29158 page
- SUSE CVE CVE-2024-29161 page
- SUSE CVE CVE-2024-29166 page
- SUSE CVE CVE-2024-32608 page
- SUSE CVE CVE-2024-32610 page
- SUSE CVE CVE-2024-32614 page
- SUSE CVE CVE-2024-32619 page
- SUSE CVE CVE-2024-32620 page
- SUSE CVE CVE-2024-33873 page
- SUSE CVE CVE-2024-33874 page
- SUSE CVE CVE-2024-33875 page
Описание
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Затронутые продукты
Ссылки
- CVE-2017-17507
- SUSE Bug 1072093
Описание
A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
Затронутые продукты
Ссылки
- CVE-2018-11205
- SUSE Bug 1093663
Описание
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Затронутые продукты
Ссылки
- CVE-2024-29158
- SUSE Bug 1224158
Описание
HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Затронутые продукты
Ссылки
- CVE-2024-29161
- SUSE Bug 1224158
Описание
HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Затронутые продукты
Ссылки
- CVE-2024-29166
- SUSE Bug 1224158
Описание
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Затронутые продукты
Ссылки
- CVE-2024-32608
- SUSE Bug 1224158
Описание
HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.
Затронутые продукты
Ссылки
- CVE-2024-32610
- SUSE Bug 1224158
Описание
HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
Затронутые продукты
Ссылки
- CVE-2024-32614
- SUSE Bug 1224158
Описание
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.
Затронутые продукты
Ссылки
- CVE-2024-32619
- SUSE Bug 1224158
Описание
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.
Затронутые продукты
Ссылки
- CVE-2024-32620
- SUSE Bug 1224158
Описание
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.
Затронутые продукты
Ссылки
- CVE-2024-33873
- SUSE Bug 1224158
Описание
HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.
Затронутые продукты
Ссылки
- CVE-2024-33874
- SUSE Bug 1224158
Описание
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.
Затронутые продукты
Ссылки
- CVE-2024-33875
- SUSE Bug 1224158