PT-2022-7542 · Hdf5+3 · Hdf5+3

Zfeixqo

·

Published

2022-01-05

·

Updated

2024-09-12

·

CVE-2021-45833

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HDF5 version 1.13.1-1
Description A Stack-based Buffer Overflow issue exists in the H5D create chunk file map hyper function in /hdf5/src/H5Dchunk.c, which can cause a Denial of Service. The vulnerability is related to writing beyond memory boundaries.
Recommendations For HDF5 version 1.13.1-1, consider disabling the H5D create chunk file map hyper function as a temporary workaround until a patch is available. Restrict access to the /hdf5/src/H5Dchunk.c file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-07116
CVE-2021-45833
ECHO-9994-51F5-3525
OPENSUSE-SU-2022_3827-1
OPENSUSE-SU-2022_3829-1
SUSE-SU-2022:3824-1
SUSE-SU-2022:3825-1
SUSE-SU-2022:3826-1
SUSE-SU-2022:3827-1
SUSE-SU-2022:3828-1
SUSE-SU-2022:3829-1

Affected Products

Debian
Hdf5
Red Os
Suse