CVE-2024-29157: Buffer Overflow
HDF5 through 1.14.3 contains a heap buffer overflow in H5HGread, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29157?
CVE-2024-29157 is classified as a high severity vulnerability due to its potential for causing denial of service and enabling code execution through a heap buffer overflow.
How do I fix CVE-2024-29157?
To fix CVE-2024-29157, users should upgrade HDF5 to version 1.14.4 or later, where the vulnerability has been resolved.
What are the potential impacts of CVE-2024-29157?
The potential impacts of CVE-2024-29157 include application crashes leading to denial of service and the possibility of remote code execution.
Which versions of HDF5 are affected by CVE-2024-29157?
CVE-2024-29157 affects HDF5 version up to and including 1.14.3.
What component of HDF5 is vulnerable in CVE-2024-29157?
CVE-2024-29157 specifically affects the H5HG_read function within HDF5, leading to a heap buffer overflow.