Heap-based Buffer Overflow in HDF5 Library
CVE-2024-33875

5.7MEDIUM

Key Information:

Vendor

HDF Group

Status
Vendor
CVE Published:
14 May 2024

What is CVE-2024-33875?

The HDF5 Library, up to version 1.14.3, contains a heap-based buffer overflow vulnerability within the H5O__layout_encode function located in H5Olayout.c. This vulnerability can lead to the corruption of the instruction pointer, potentially allowing an attacker to execute arbitrary code within affected applications. Users relying on the HDF5 Library should promptly upgrade to the latest version to mitigate risks associated with this vulnerability and enhance overall security of their software.

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.