CVE-2016-4330: Buffer Overflow
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4330?
CVE-2016-4330 has been rated as a high severity vulnerability due to its potential for heap-based buffer overflow and arbitrary code execution.
How do I fix CVE-2016-4330?
To fix CVE-2016-4330, update HDF5 to version 1.8.17 or later, which addresses this vulnerability.
What is the impact of CVE-2016-4330?
The impact of CVE-2016-4330 may include potential arbitrary code execution, allowing an attacker to manipulate system operations.
Which versions of HDF5 are affected by CVE-2016-4330?
CVE-2016-4330 affects HDF5 version 1.8.16 specifically.
Is CVE-2016-4330 exploitable remotely?
CVE-2016-4330 can be exploited remotely if an attacker can provide specially crafted data to an application using the vulnerable HDF5 library.