PT-2017-14819 · Hdf+2 · Hdf5+2
Published
2017-12-11
·
Updated
2022-06-03
·
CVE-2017-17508
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
HDF5 version 1.10.1
Description
The issue is related to a divide-by-zero error in the H5T set loc function, located in the H5T.c file within libhdf5.a. This can cause applications like h5dump to crash when opening a specially crafted HDF5 file.
Recommendations
For HDF5 version 1.10.1, consider avoiding the use of the H5T set loc function until a patch is available. As a temporary workaround, restrict the opening of untrusted HDF5 files to prevent potential crashes.
Exploit
Fix
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hdf5
Suse
Ubuntu