CVE-2020-10811: Medium severity HDFGroup hdf5 vulnerability
Published Mar 22, 2020
·Updated
An issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5Olayoutdecode() located in H5Olayout.c. It allows an attacker to cause Denial of Service.
Affected Software
1 affected component
HDFGroup hdf5<=1.12.0
Event History
Mar 22, 2020
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10811?
CVE-2020-10811 is classified as a high severity vulnerability due to its potential to cause Denial of Service.
2
How do I fix CVE-2020-10811?
To fix CVE-2020-10811, upgrade HDF5 to version 1.12.1 or later, where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2020-10811?
CVE-2020-10811 is a heap-based buffer over-read vulnerability affecting HDF5.
4
What can attackers do with CVE-2020-10811?
Attackers can exploit CVE-2020-10811 to cause Denial of Service, disrupting software that relies on HDF5.
5
Which versions of HDF5 are affected by CVE-2020-10811?
HDF5 versions up to and including 1.12.0 are affected by CVE-2020-10811.