CVE-2018-17437: Medium severity hdf5 vulnerability
Published Sep 24, 2018
·Updated
Memory leak in the H5Odtypedecodehelper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
Affected Software
1 affected component
HDFGroup hdf5<=1.10.3
Event History
Sep 24, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17437?
CVE-2018-17437 is classified as a denial of service vulnerability due to a memory leak.
2
How do I fix CVE-2018-17437?
To fix CVE-2018-17437, upgrade the HDF5 library to version 1.10.4 or later.
3
What causes CVE-2018-17437?
CVE-2018-17437 is caused by a memory leak in the H5O_dtype_decode_helper() function when handling crafted HDF5 files.
4
Which versions of HDF5 are affected by CVE-2018-17437?
CVE-2018-17437 affects HDF5 versions up to and including 1.10.3.
5
What is the impact of CVE-2018-17437 on systems?
The impact of CVE-2018-17437 is the potential for denial of service due to excessive memory consumption.