REDHAT-BUG-2441088: Buffer Overflow
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HDF5to a version that resolves this vulnerability.Fixed in 1.14.4-2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2441088?
The severity of REDHAT-BUG-2441088 is high with a score of 7.
What type of vulnerability is described in REDHAT-BUG-2441088?
REDHAT-BUG-2441088 describes a buffer overflow vulnerability in HDF5.
How can REDHAT-BUG-2441088 be exploited?
An attacker can exploit REDHAT-BUG-2441088 by controlling an `h5` file parsed by HDF5 to trigger a write-based heap buffer overflow.
What are the potential consequences of REDHAT-BUG-2441088?
The potential consequences of REDHAT-BUG-2441088 include denial-of-service conditions and possible remote code execution.
How do I fix REDHAT-BUG-2441088?
To fix REDHAT-BUG-2441088, upgrade to HDF5 version 1.14.4-2 or later.