First published: Mon Feb 25 2019(Updated: )
An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5MM_xstrdup in H5MM.c when called from H5O_dtype_decode_helper in H5Odtype.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | =1.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9152 has been rated as a high severity vulnerability due to its potential to expose sensitive data through an out of bounds read.
To fix CVE-2019-9152, upgrade the HDF5 library to version 1.10.5 or later where the vulnerability has been addressed.
CVE-2019-9152 may allow attackers to read out of bounds memory, potentially leading to information disclosure.
CVE-2019-9152 is primarily a local vulnerability, as it affects how the HDF5 library handles certain data in memory.
Users and applications utilizing HDF5 version 1.10.4 are affected by CVE-2019-9152.