First published: Tue Aug 21 2018(Updated: )
An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | =1.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15671 has a high severity level due to the potential for denial of service attacks.
To fix CVE-2018-15671, upgrade to a later version of the HDF5 library that has addressed the stack consumption issue.
The impact of CVE-2018-15671 is denial of service resulting from excessive stack consumption when parsing crafted HDF files.
CVE-2018-15671 specifically affects HDF5 version 1.10.2.
CVE-2018-15671 can be exploited by providing a specially crafted HDF file that triggers excessive stack consumption.