CVE-2024-32616: High severity hdf5 vulnerability
Published May 14, 2024
·Updated
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5Odtypeencodehelper in H5Odtype.c.
Affected Software
2 affected components
HDFGroup hdf5<1.14.4
HDF Group HDF5 Library<1.14.3
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:36 PM
Aug 2, 2024
Data Sourced
via MITRE·02:18 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-32616?
CVE-2024-32616 is considered a moderate severity vulnerability due to its potential for causing heap-based buffer over-read issues.
2
How do I fix CVE-2024-32616?
To fix CVE-2024-32616, upgrade your HDF5 Library to version 1.14.4 or later.
3
What is a heap-based buffer over-read in CVE-2024-32616?
A heap-based buffer over-read in CVE-2024-32616 occurs when the application reads more memory than intended, which can lead to data leakage.
4
Which versions of HDF5 Library are affected by CVE-2024-32616?
CVE-2024-32616 affects HDF5 Library versions prior to 1.14.4.
5
Who is affected by CVE-2024-32616?
Any user or organization using HDF5 Library versions 1.14.3 and earlier is affected by CVE-2024-32616.