PT-2018-12289 · Hdf+2 · Hdf5+2

Published

2018-07-13

·

Updated

2026-03-29

·

CVE-2018-14033

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HDF5 version 1.8.20
Description A heap-based buffer over-read issue was discovered in the HDF5 library, specifically in the function H5O layout decode in H5Olayout.c. This issue is related to the HDmemcpy function.
Recommendations For version 1.8.20, consider applying a patch or fix that addresses the heap-based buffer over-read in the H5O layout decode function. As a temporary workaround, consider restricting access to the H5O layout decode function until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14033
ECHO-0707-183D-ABEA
OESA-2023-1325
OESA-2023-1326
OESA-2023-1328
OPENSUSE-SU-2022_1912-1
SUSE-SU-2022:1903-1
SUSE-SU-2022:1910-1
SUSE-SU-2022:1911-1
SUSE-SU-2022:1912-1
SUSE-SU-2022:1933-1

Affected Products

Debian
Hdf5
Suse