CVE-2017-17505: Null Pointer Dereference
Published Dec 11, 2017
·Updated
In HDF5 1.10.1, there is a NULL pointer dereference in the function H5Oplinedecode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Affected Software
1 affected component
HDFGroup hdf5=1.10.1
Event History
Dec 11, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17505?
The severity of CVE-2017-17505 is rated as medium with a score of 6.5.
2
How do I fix CVE-2017-17505?
To fix CVE-2017-17505, upgrade to a version of HDF5 later than 1.10.1 that includes the vulnerability patch.
3
What is the impact of CVE-2017-17505?
The impact of CVE-2017-17505 is a NULL pointer dereference that can cause h5dump to crash when opening a crafted HDF5 file.
4
Which software is affected by CVE-2017-17505?
CVE-2017-17505 affects HDF5 version 1.10.1 from HDF Group.
5
What is the vulnerability type of CVE-2017-17505?
CVE-2017-17505 is classified as a NULL pointer dereference vulnerability, which is identified by CWE-476.