First published: Sun Feb 17 2019(Updated: )
A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while repacking an HDF5 file, aka "Invalid write of size 2."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | <=1.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8396 is classified as a high severity vulnerability due to the potential for denial of service attacks.
To fix CVE-2019-8396, upgrade HDF5 to the latest version beyond 1.10.4 where the vulnerability has been addressed.
CVE-2019-8396 allows an attacker to induce a denial of service by exploiting a buffer overflow when processing crafted HDF5 files.
CVE-2019-8396 affects all versions of HDF5 up to and including 1.10.4.
To determine if you are vulnerable to CVE-2019-8396, check if your installation of HDF5 is version 1.10.4 or earlier.