First published: Mon Dec 11 2017(Updated: )
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | =1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17507 is classified as a high severity vulnerability due to the potential for out of bounds read which can lead to application crashes.
To fix CVE-2017-17507, upgrade HDF5 to version 1.10.2 or later where the vulnerability has been addressed.
CVE-2017-17507 specifically affects HDF5 version 1.10.1.
The impacts of CVE-2017-17507 include potential crashes of applications such as h5dump when handling crafted HDF5 files.
Yes, CVE-2017-17507 can be exploited remotely if a user is tricked into opening a malicious HDF5 file.