PT-2018-1923 · Hdf+2 · Hdf5+2

CVE-2018-17434

·

Published

2018-09-24

·

Updated

2023-08-09

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HDF5 versions 1.10.3 and earlier
Description A SIGFPE signal is raised in the apply filters() function of h5repack filters.c due to incorrect protection against division by zero when parsing a crafted HDF file. This could allow a remote denial of service attack.
Recommendations For versions 1.10.3 and earlier, consider disabling the apply filters() function as a temporary workaround until a patch is available. Restrict access to crafted HDF files to minimize the risk of exploitation.

Exploit

Fix

DoS

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01530
CVE-2018-17434
DLA-3522-1
OPENSUSE-SU-2022_1912-1
SUSE-SU-2022:1903-1
SUSE-SU-2022:1910-1
SUSE-SU-2022:1911-1
SUSE-SU-2022:1912-1
SUSE-SU-2022:1933-1

Affected Products

Astra Linux
Hdf5
Suse