CVE-2017-17507: Medium severity hdf5 vulnerability
Published Dec 11, 2017
·Updated
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Tconvstructopt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Affected Software
1 affected component
HDFGroup hdf5=1.10.1
Event History
Dec 11, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17507?
CVE-2017-17507 is classified as a high severity vulnerability due to the potential for out of bounds read which can lead to application crashes.
2
How do I fix CVE-2017-17507?
To fix CVE-2017-17507, upgrade HDF5 to version 1.10.2 or later where the vulnerability has been addressed.
3
What software is affected by CVE-2017-17507?
CVE-2017-17507 specifically affects HDF5 version 1.10.1.
4
What are the impacts of CVE-2017-17507?
The impacts of CVE-2017-17507 include potential crashes of applications such as h5dump when handling crafted HDF5 files.
5
Can CVE-2017-17507 be exploited remotely?
Yes, CVE-2017-17507 can be exploited remotely if a user is tricked into opening a malicious HDF5 file.