First published: Mon Sep 24 2018(Updated: )
An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | =1.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17439 is rated as a high-severity vulnerability due to the potential for remote execution of code exploiting a stack-based buffer overflow.
To fix CVE-2018-17439, update to a patched version of the HDF5 library that resolves the stack-based buffer overflow issue.
CVE-2018-17439 affects HDF5 version 1.10.3 specifically.
CVE-2018-17439 is a stack-based buffer overflow that occurs in the function H5S_extent_get_dims() during file format conversion.
CVE-2018-17439 can be exploited by an attacker who manipulates an HDF5 file to trigger the buffer overflow when converting to a GIF file.