First published: Tue Jul 10 2018(Updated: )
An issue was discovered in the HDF HDF5 1.8.20 library. There is a stack-based buffer overflow in the function H5FD_sec2_read in H5FDsec2.c, related to HDread.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | =1.8.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13876 is rated as a critical vulnerability due to the stack-based buffer overflow which can lead to arbitrary code execution.
To fix CVE-2018-13876, upgrade the HDF5 library to version 1.10.0 or later.
CVE-2018-13876 specifically affects HDF5 version 1.8.20.
CVE-2018-13876 is a stack-based buffer overflow vulnerability.
The vulnerability in CVE-2018-13876 is found in the function H5FD_sec2_read in H5FDsec2.c.