CVE-2018-17432: Null Pointer Dereference
Published Sep 24, 2018
·Updated
A NULL pointer dereference in H5Osdspaceencode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.
Affected Software
1 affected component
HDFGroup hdf5<=1.10.3
Event History
Sep 24, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17432?
CVE-2018-17432 has a severity rating that indicates it can lead to a denial of service attack.
2
How do I fix CVE-2018-17432?
To fix CVE-2018-17432, upgrade HDF5 to version 1.10.4 or later.
3
What impact does CVE-2018-17432 have on systems?
CVE-2018-17432 can cause denial of service by crashing the application processing a vulnerable HDF5 file.
4
Is CVE-2018-17432 exploitable remotely?
Yes, CVE-2018-17432 is exploitable remotely if an attacker can provide a crafted HDF5 file.
5
Which versions of HDF5 are affected by CVE-2018-17432?
CVE-2018-17432 affects HDF5 versions up to and including 1.10.3.