CVE-2017-17508: Divide by Zero
Published Dec 11, 2017
·Updated
In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5Tsetloc in the H5T.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Affected Software
1 affected component
HDFGroup hdf5=1.10.1
Event History
Dec 11, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17508?
CVE-2017-17508 is considered a high severity vulnerability due to the potential for application crashes.
2
How do I fix CVE-2017-17508?
To fix CVE-2017-17508, upgrade to a patched version of HDF5 that addresses this divide-by-zero vulnerability.
3
What are the consequences of exploiting CVE-2017-17508?
Exploiting CVE-2017-17508 can lead to application crashes and may compromise data integrity when handling crafted HDF5 files.
4
Which software is affected by CVE-2017-17508?
CVE-2017-17508 specifically affects HDF5 version 1.10.1.
5
What component of HDF5 does CVE-2017-17508 affect?
CVE-2017-17508 affects the H5T_set_loc function in the H5T.c file within the libhdf5.a library.