CVE-2018-13875: High severity hdf5 vulnerability
Published Jul 10, 2018
·Updated
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out-of-bounds read in the function H5VMmemcpyvv in H5VM.c.
Affected Software
1 affected component
HDFGroup hdf5=1.8.20
Event History
Jul 10, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13875?
CVE-2018-13875 has been classified as having a medium severity due to the potential for out-of-bounds read vulnerabilities.
2
How do I fix CVE-2018-13875?
To fix CVE-2018-13875, upgrade the HDF5 library to the latest version beyond 1.8.20 that addresses this vulnerability.
3
What software is affected by CVE-2018-13875?
CVE-2018-13875 specifically affects HDF5 version 1.8.20.
4
Can exploiting CVE-2018-13875 lead to data breaches?
Yes, exploiting CVE-2018-13875 could potentially disclose sensitive data due to the out-of-bounds read.
5
What does the function H5VM_memcpyvv do in relation to CVE-2018-13875?
The function H5VM_memcpyvv in H5VM.c is responsible for processing memory operations, and it is where the out-of-bounds read vulnerability occurs.