Heap-Based Buffer Overflow in HDF5 Library Affects Data Handling
CVE-2024-32623

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
14 May 2024

What is CVE-2024-32623?

The HDF5 Library, a widely-used framework for storing and managing large amounts of data, has a vulnerability related to a heap-based buffer overflow in the function H5VM_array_fill, which is invoked from H5S_select_elements. This flaw can potentially compromise data integrity, allowing for unintended manipulation of data within applications that utilize the affected versions of the library. Users and developers utilizing HDF5 versions prior to 1.14.4 should be aware of this issue and consider upgrading to mitigate potential risks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-32623 : Heap-Based Buffer Overflow in HDF5 Library Affects Data Handling