CVE-2018-13873: Critical severity hdf5 vulnerability
Published Jul 10, 2018
·Updated
An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5Ochunkdeserialize in H5Ocache.c.
Affected Software
2 affected components
HDFGroup hdf5=1.8.20
HDFGroup hdf5>=1.8.0<=1.8.20
Event History
Jul 10, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13873?
CVE-2018-13873 has a severity rating that can impact the confidentiality and integrity of information due to the buffer over-read vulnerability.
2
How do I fix CVE-2018-13873?
To fix CVE-2018-13873, you should upgrade to a patched version of the HDF5 library that addresses this vulnerability.
3
What can be exploited in CVE-2018-13873?
CVE-2018-13873 can be exploited to read beyond allocated buffer boundaries, potentially leaking sensitive information.
4
Which versions of HDF5 are affected by CVE-2018-13873?
CVE-2018-13873 specifically affects HDF5 version 1.8.20.
5
Is CVE-2018-13873 a serious issue for users of HDF5?
Yes, CVE-2018-13873 presents a serious risk as it involves a buffer over-read that could expose sensitive data.