PT-2024-6208 · Unknown+2 · Hdf5 Library+2
Published
2024-05-09
·
Updated
2024-11-08
·
CVE-2024-32609
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HDF5 Library versions prior to 1.14.4
Description
The issue is related to the function
H5E printf stack() in the file H5Eint.c of the HDF5 Library, which is associated with uncontrolled recursion. This can lead to stack consumption. Exploitation of the issue may allow a remote attacker to disclose protected information.Recommendations
For versions prior to 1.14.4, update to a version that contains a fix for this issue.
As a temporary workaround, consider disabling the
H5E printf stack() function until a patch is available.Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Hdf5 Library
Red Os