PT-2024-6210 · Unknown+2 · Hdf5 Library+2

Published

2024-05-09

·

Updated

2024-11-08

·

CVE-2024-32607

CVSS v3.1

5.7

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions HDF5 Library versions prior to 1.14.4
Description The issue is related to a buffer overflow in the heap, caused by the H5A close() function in the H5Aint.c file of the HDF5 library, leading to corruption of the instruction pointer. This can be exploited to cause a denial of service.
Recommendations For versions prior to 1.14.4, update to version 1.14.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the H5A close() function in the H5Aint.c file until a patch is available.

Fix

Out of bounds Read

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-40550
AZL-40727
BDU:2024-07141
CVE-2024-32607
ECHO-C69F-D332-49F9
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340

Affected Products

Debian
Hdf5 Library
Red Os