Heap-based Buffer Over-Read in HDF5 Library by The HDF Group
CVE-2018-13870
9.8CRITICAL
What is CVE-2018-13870?
A vulnerability has been identified in the HDF5 library, specifically in version 1.8.20, where a heap-based buffer over-read occurs in the H5O_link_decode function within H5Olink.c. This flaw may lead to unintended data exposure and can be exploited by malicious users to read sensitive information from memory, potentially compromising application security.
