PT-2017-14819 · Hdf+2 · Hdf5+2

Publicado

2017-12-11

·

Atualizado

2022-06-03

·

CVE-2017-17508

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HDF5 version 1.10.1
Description The issue is related to a divide-by-zero error in the H5T set loc function, located in the H5T.c file within libhdf5.a. This can cause applications like h5dump to crash when opening a specially crafted HDF5 file.
Recommendations For HDF5 version 1.10.1, consider avoiding the use of the H5T set loc function until a patch is available. As a temporary workaround, restrict the opening of untrusted HDF5 files to prevent potential crashes.

Exploit

Correção

Divide By Zero

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17508
SUSE-SU-2022:1903-1
SUSE-SU-2022:1910-1
SUSE-SU-2022:1911-1
SUSE-SU-2022:1933-1
USN-4817-1

Produtos afetados

Hdf5
Suse
Ubuntu