First published: Tue May 14 2024(Updated: )
HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HDF5 | <1.14.4 | |
HDF5 | <=1.14.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-32605 has been classified as a high severity vulnerability due to its potential impact on memory corruption and application crashes.
To fix CVE-2024-32605, upgrade to HDF5 Library version 1.14.4 or later.
CVE-2024-32605 is caused by a heap-based buffer over-read in the H5VM_memcpyvv function within the HDF5 Library.
CVE-2024-32605 affects HDF5 Library versions up to and including 1.14.3.
CVE-2024-32605 may be exploitable remotely if an application that uses the affected HDF5 Library is exposed to untrusted inputs.