CVE-2020-10812: Null Pointer Dereference
Published Mar 22, 2020
·Updated
An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5Fgetnrefs() located in H5Fquery.c. It allows an attacker to cause Denial of Service.
Affected Software
1 affected component
HDFGroup hdf5<=1.12.0
Event History
Mar 22, 2020
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10812?
CVE-2020-10812 has been classified with a severity level that indicates it can lead to Denial of Service.
2
How do I fix CVE-2020-10812?
To fix CVE-2020-10812, upgrade HDF5 to version 1.12.1 or later, where the vulnerability has been addressed.
3
What specific function is responsible for the vulnerability in CVE-2020-10812?
The NULL pointer dereference vulnerability in CVE-2020-10812 affects the function H5F_get_nrefs() in the HDF5 library.
4
What versions of HDF5 are affected by CVE-2020-10812?
CVE-2020-10812 affects HDF5 versions up to and including 1.12.0.
5
Is there a workaround for CVE-2020-10812?
There is no specific workaround defined for CVE-2020-10812 besides upgrading to a patched version.