PT-2022-7537 · Hdf5+2 · Hdf5+2

Published

2022-08-22

·

Updated

2024-11-08

·

CVE-2024-29159

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HDF5 versions 1.14.3 and earlier
Description The issue is related to a buffer overflow in the H5Z filter scaleoffset function of the HDF5 library. This overflow occurs due to the lack of size checking for input data during the copying process. The exploitation of this issue can lead to the corruption of the instruction pointer, resulting in denial of service or potential code execution. It may also allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For HDF5 versions 1.14.3 and earlier, as a temporary workaround, consider disabling the H5Z filter scaleoffset function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-40637
AZL-40663
BDU:2024-07111
CVE-2024-29159
ECHO-D2E4-5F54-947B
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340
RHSA-2025:3801

Affected Products

Debian
Hdf5
Red Os