PT-2021-21415 · Matio+1 · Matio+1

Published

2021-07-20

·

Updated

2022-12-13

·

CVE-2021-36977

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions matio (aka MAT File I/O Library) versions 1.5.20 through 1.5.21
Description The issue is related to a heap-based buffer overflow in the H5MM memcpy function, which is called from H5MM malloc and H5C load entry. This overflow is associated with the use of HDF5 version 1.12.0.
Recommendations For matio versions 1.5.20 and 1.5.21, consider restricting the use of the H5MM memcpy function until a patch is available. As a temporary workaround, avoid using the H5MM malloc and H5C load entry functions that call H5MM memcpy to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36977
MGASA-2022-0465
OPENSUSE-SU-2022:10235-1

Affected Products

Hdf5
Matio