Heap-based Buffer Over-read in HDF5 Library by The HDF Group
CVE-2024-32616

7.4HIGH

Key Information:

Status
Vendor
CVE Published:
14 May 2024

What is CVE-2024-32616?

The HDF5 Library, a widely used framework for managing and storing data, is impacted by a heap-based buffer over-read vulnerability that resides in the H5O__dtype_encode_helper function within the H5Odtype.c source file. This flaw can be exploited during data encoding processes, potentially allowing attackers to access sensitive information that should remain protected. It is crucial for users of HDF5 Library versions 1.14.3 and earlier to update to version 1.14.4 or later to mitigate this security risk.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-32616 : Heap-based Buffer Over-read in HDF5 Library by The HDF Group