CVE-2018-17433: Buffer Overflow
Published Sep 24, 2018
·Updated
A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
Affected Software
1 affected component
HDFGroup hdf5<=1.10.3
Event History
Sep 24, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17433?
The severity of CVE-2018-17433 is medium with a CVSS score of 6.5.
2
How does the heap-based buffer overflow in CVE-2018-17433 occur?
The heap-based buffer overflow in CVE-2018-17433 occurs in ReadGifImageDesc() in gifread.c in the HDF HDF5 library when converting a GIF file to an HDF file.
3
What can attackers do with CVE-2018-17433 vulnerability?
Attackers can cause a denial of service via a crafted HDF5 file exploiting CVE-2018-17433.
4
Is there a fix available for CVE-2018-17433?
It is recommended to update the HDF HDF5 library to a version beyond 1.10.3 to mitigate CVE-2018-17433 vulnerability.
5
Which CWE IDs are associated with CVE-2018-17433?
CVE-2018-17433 is associated with CWE-119 and CWE-787.