PT-2022-7547 · Hdf5+2 · Hdf5+2

Published

2022-08-22

·

Updated

2024-11-08

·

CVE-2024-29163

CVSS v3.1

7.4

High

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HDF5 versions 1.14.3 and earlier
Description The issue is related to a heap buffer overflow in the H5T bit find() function of the HDF5 library. This overflow can cause corruption of the instruction pointer, leading to denial of service or potential code execution. The exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For HDF5 versions 1.14.3 and earlier, as a temporary workaround, consider disabling the H5T bit find() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-40649
AZL-40696
BDU:2024-07147
CVE-2024-29163
ECHO-CED4-0515-6955
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340
RHSA-2025:3801

Affected Products

Debian
Hdf5
Red Os