CVE-2017-17509: High severity HDFGroup hdf5 vulnerability
In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5Gentdecodevec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17509?
CVE-2017-17509 is rated as a high severity vulnerability due to the potential for crash or undefined behavior upon exploiting the out of bounds write issue.
How do I fix CVE-2017-17509?
To fix CVE-2017-17509, upgrade to HDF5 version 1.10.2 or later, where the vulnerability has been addressed.
What types of systems are affected by CVE-2017-17509?
CVE-2017-17509 affects systems using HDF5 version 1.10.1 specifically, which includes applications utilizing libhdf5.a.
What kind of impact can CVE-2017-17509 have?
The impact of CVE-2017-17509 can range from application crashes to potentially executing arbitrary code when a crafted HDF5 file is processed.
Is there a known exploit for CVE-2017-17509?
While there are reports of crashes associated with CVE-2017-17509, specific exploit details have not been publicly disclosed.