CVE-2018-17436: Medium severity hdf5 vulnerability
Published Sep 24, 2018
·Updated
ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
Affected Software
1 affected component
HDFGroup hdf5<=1.10.3
Event History
Sep 24, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17436?
CVE-2018-17436 is classified as a denial of service vulnerability due to invalid write access.
2
How do I fix CVE-2018-17436?
To mitigate CVE-2018-17436, update the HDF5 library to a version newer than 1.10.3.
3
What kind of attack does CVE-2018-17436 enable?
CVE-2018-17436 allows attackers to cause a denial of service through crafted HDF5 files.
4
In which version of HDF5 is CVE-2018-17436 present?
CVE-2018-17436 affects HDF5 versions up to and including 1.10.3.
5
What component of HDF5 does CVE-2018-17436 impact?
CVE-2018-17436 impacts the ReadCode() function in the decompress.c file.