PT-2018-12289 · Hdf+2 · Hdf5+2
Published
2018-07-13
·
Updated
2026-03-29
·
CVE-2018-14033
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HDF5 version 1.8.20
Description
A heap-based buffer over-read issue was discovered in the HDF5 library, specifically in the function H5O layout decode in H5Olayout.c. This issue is related to the HDmemcpy function.
Recommendations
For version 1.8.20, consider applying a patch or fix that addresses the heap-based buffer over-read in the H5O layout decode function. As a temporary workaround, consider restricting access to the H5O layout decode function until a patch is available.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Hdf5
Suse