CVE-2024-32623: Buffer Overflow
Published May 14, 2024
·Updated
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VMarrayfill in H5VM.c (called from H5Sselectelements in H5Spoint.c).
Affected Software
2 affected components
HDFGroup hdf5<1.14.4
HDF Group HDF5 Library<=1.14.3
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:36 PM
Aug 2, 2024
Data Sourced
via MITRE·02:18 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-32623?
CVE-2024-32623 has been classified as a high severity vulnerability due to its potential to cause a heap-based buffer overflow.
2
How do I fix CVE-2024-32623?
To fix CVE-2024-32623, upgrade your HDF5 Library to version 1.14.4 or later.
3
What types of systems are affected by CVE-2024-32623?
CVE-2024-32623 affects all versions of the HDF5 Library up to version 1.14.3.
4
What is a heap-based buffer overflow in the context of CVE-2024-32623?
A heap-based buffer overflow in CVE-2024-32623 allows attackers to exploit memory management flaws to execute arbitrary code.
5
Is CVE-2024-32623 exploitable remotely?
Yes, CVE-2024-32623 can potentially be exploited remotely if the vulnerable application allows untrusted input.