CVE-2016-4331: High severity hdf5 vulnerability
Published Nov 18, 2016
·Updated
When decoding data out of a dataset encoded with the H5ZNBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
Affected Software
1 affected component
HDFGroup hdf5=1.8.16
Event History
Nov 18, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4331?
CVE-2016-4331 has a severity rating that indicates a risk of arbitrary code execution.
2
How do I fix CVE-2016-4331?
To fix CVE-2016-4331, upgrade the HDF5 library to a version that includes the necessary security patches.
3
What software is affected by CVE-2016-4331?
CVE-2016-4331 specifically affects HDF5 version 1.8.16.
4
What is the impact of CVE-2016-4331?
The impact of CVE-2016-4331 is the potential for an attacker to execute arbitrary code on the system.
5
Who reported CVE-2016-4331?
CVE-2016-4331 was reported following a discovery of vulnerabilities in the HDF5 library used in various applications.