PT-2018-1923 · Hdf+2 · Hdf5+2
Published
2018-09-24
·
Updated
2023-08-09
·
CVE-2018-17434
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
HDF5 versions 1.10.3 and earlier
Description
A SIGFPE signal is raised in the
apply filters() function of h5repack filters.c due to incorrect protection against division by zero when parsing a crafted HDF file. This could allow a remote denial of service attack.Recommendations
For versions 1.10.3 and earlier, consider disabling the
apply filters() function as a temporary workaround until a patch is available. Restrict access to crafted HDF files to minimize the risk of exploitation.Exploit
Fix
DoS
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Hdf5
Suse