PT-2022-7543 · Hdf5+3 · Hdf5+3

Zfeixqo

·

Published

2022-01-05

·

Updated

2024-09-12

·

CVE-2021-45830

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HDF5 version 1.13.1-1
Description A heap-based buffer overflow issue exists in the H5F addr decode len() function, located in the /hdf5/src/H5Fint.c file, which could cause a Denial of Service. This issue is related to writing beyond the boundaries of memory.
Recommendations For HDF5 version 1.13.1-1, consider disabling the H5F addr decode len() function as a temporary workaround until a patch is available. Restrict access to the /hdf5/src/H5Fint.c file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-07117
CVE-2021-45830
ECHO-4C41-09E9-A4F3
OPENSUSE-SU-2022_3827-1
OPENSUSE-SU-2022_3829-1
SUSE-SU-2022:3824-1
SUSE-SU-2022:3825-1
SUSE-SU-2022:3826-1
SUSE-SU-2022:3827-1
SUSE-SU-2022:3828-1
SUSE-SU-2022:3829-1

Affected Products

Debian
Hdf5
Red Os
Suse