First published: Fri Nov 18 2016(Updated: )
When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | =1.8.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4331 has a severity rating that indicates a risk of arbitrary code execution.
To fix CVE-2016-4331, upgrade the HDF5 library to a version that includes the necessary security patches.
CVE-2016-4331 specifically affects HDF5 version 1.8.16.
The impact of CVE-2016-4331 is the potential for an attacker to execute arbitrary code on the system.
CVE-2016-4331 was reported following a discovery of vulnerabilities in the HDF5 library used in various applications.