Heap-based Buffer Over-read Vulnerability in HDF5 Library
CVE-2024-32620
7.4HIGH
What is CVE-2024-32620?
The HDF5 Library, up to version 1.14.3, is susceptible to a heap-based buffer over-read vulnerability within the function H5F_addr_decode_len located in H5Fint.c. This flaw can potentially lead to the corruption of the instruction pointer, posing a risk to the integrity and execution of the software. Remediation is available in version 1.14.4, where the issue has been addressed to enhance security and prevent exploitation.