First published: Sun Mar 22 2020(Updated: )
An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | <=1.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10809 has been classified as a high severity vulnerability due to its potential for Denial of Service attacks.
To fix CVE-2020-10809, it is recommended to upgrade to HDF5 version 1.12.1 or later.
CVE-2020-10809 is caused by a heap-based buffer overflow in the Decompress() function in decompress.c when processing crafted files.
As of now, specific exploit attempts for CVE-2020-10809 have not been widely reported, but the potential for Denial of Service exists.
CVE-2020-10809 affects versions of HDF5 up to and including 1.12.0.