PT-2024-6200 · Unknown+2 · Hdf5 Library+2

Published

2024-05-09

·

Updated

2026-03-29

·

CVE-2024-32617

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HDF5 Library versions prior to 1.14.4
Description The issue is related to a heap-based buffer over-read caused by the unsafe use of strdup in H5MM xstrdup in H5MM.c, which can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The H5MM xstrdup function is called from H5G ent to link in H5Glink.c.
Recommendations For versions prior to 1.14.4, consider updating to a version that contains a fix for this issue, as the current version may allow for exploitation due to the unsafe use of strdup in H5MM xstrdup. As a temporary workaround, consider restricting the use of the H5MM xstrdup function until a patch is available.

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-40693
BDU:2024-07131
CVE-2024-32617
ECHO-62B8-216B-D6A2
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340
RHSA-2025:3801

Affected Products

Debian
Hdf5 Library
Red Os