PT-2022-4361 · Hdf5+3 · Libhdf5+3

Dave Mcdaniel

·

Published

2022-08-22

·

Updated

2024-09-12

·

CVE-2022-25972

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HDF5 Group libhdf5 version 1.10.4
Description An out-of-bounds write issue exists in the gif2h5 functionality, allowing code execution through a specially-crafted GIF file. An attacker can trigger this issue by providing a malicious file, potentially enabling them to execute arbitrary code on the target system.
Recommendations For version 1.10.4, consider avoiding the use of the gif2h5 functionality until a patch is available. As a temporary workaround, restrict the opening of GIF files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2022-05221
CVE-2022-25972
ECHO-1E97-B296-D554

Affected Products

Astra Linux
Debian
Red Os
Libhdf5