PT-2018-1923 · Hdf+2 · Hdf5+2

Published

2018-09-24

·

Updated

2023-08-09

·

CVE-2018-17434

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HDF5 versions 1.10.3 and earlier
Description A SIGFPE signal is raised in the apply filters() function of h5repack filters.c due to incorrect protection against division by zero when parsing a crafted HDF file. This could allow a remote denial of service attack.
Recommendations For versions 1.10.3 and earlier, consider disabling the apply filters() function as a temporary workaround until a patch is available. Restrict access to crafted HDF files to minimize the risk of exploitation.

Exploit

Fix

DoS

Divide By Zero

Weakness Enumeration

Related Identifiers

BDU:2018-01530
CVE-2018-17434
DLA-3522-1
OPENSUSE-SU-2022_1912-1
SUSE-SU-2022:1903-1
SUSE-SU-2022:1910-1
SUSE-SU-2022:1911-1
SUSE-SU-2022:1912-1
SUSE-SU-2022:1933-1

Affected Products

Astra Linux
Hdf5
Suse