PT-2018-3951 · Hdf5+4 · Hdf5+4

Published

2018-09-20

·

Updated

2023-08-09

·

CVE-2018-17237

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HDF5 version 1.10.3
Description The issue arises from incorrect protection against division by zero in the H5D chunk set info real() function of the H5Dchunk.c component in the HDF5 library. This can lead to a SIGFPE signal being raised when attempting to parse a crafted HDF file. The vulnerability may allow a remote attacker to cause a denial of service using a specially crafted HDF file.
Recommendations For HDF5 version 1.10.3, consider applying a patch or fix that addresses the division by zero issue in the H5D chunk set info real() function to prevent potential denial of service attacks.

Exploit

Fix

Divide By Zero

Weakness Enumeration

Related Identifiers

BDU:2023-07648
CVE-2018-17237
DLA-3522-1
OPENSUSE-SU-2022_1912-1
SUSE-SU-2022:1903-1
SUSE-SU-2022:1910-1
SUSE-SU-2022:1911-1
SUSE-SU-2022:1912-1
SUSE-SU-2022:1933-1
USN-5272-1

Affected Products

Astra Linux
Hdf5
Linuxmint
Suse
Ubuntu