Heap-based Buffer Over-read in HDF5 Library by The HDF Group
CVE-2024-32616
7.4HIGH
What is CVE-2024-32616?
The HDF5 Library, a widely used framework for managing and storing data, is impacted by a heap-based buffer over-read vulnerability that resides in the H5O__dtype_encode_helper function within the H5Odtype.c source file. This flaw can be exploited during data encoding processes, potentially allowing attackers to access sensitive information that should remain protected. It is crucial for users of HDF5 Library versions 1.14.3 and earlier to update to version 1.14.4 or later to mitigate this security risk.