CVE-2016-4330
published 2016-11-18CVE-2016-4330: In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a…
PriorityP336high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.80%
52.5th percentile
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | < hdf5 1.10.0-patch1+docs-1 (bookworm) | hdf5 1.10.0-patch1+docs-1 (bookworm) |
| hdfgroup | hdf5 | — | — |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| perl | perl | >= 0 < 5.18.2-2ubuntu1.1 | 5.18.2-2ubuntu1.1 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hdf5: H5T_ARRAY heap buffer overflow
vendor_redhat·2016-11-15·CVSS 8.6
CVE-2016-4330 [HIGH] CWE-122 hdf5: H5T_ARRAY heap buffer overflow
hdf5: H5T_ARRAY heap buffer overflow
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
Multiple heap overflows were found in HDF5. These issues could be used to gain code execution in any program that exposes the affected functions to untrusted input. While HDF5 is shipped as a dependency, no Red Hat products are known to expose these issues in any supported use case at this time.
Package: hdf5 (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Package: hdf5 (Red Hat OpenShift Enterprise 2) - Will not fix
Package: hdf5 (Red Hat OpenStack Platform 10 (Newton)) - Will not f
Debian
CVE-2016-4330: hdf5 - In the HDF5 1.8.16 library's failure to check if the number of dimensions for an...
vendor_debian·2016·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330: hdf5 - In the HDF5 1.8.16 library's failure to check if the number of dimensions for an...
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 1.10.0-patch1+docs-1)
bullseye: resolved (fixed in 1.10.0-patch1+docs-1)
forky: resolved (fixed in 1.10.0-patch1+docs-1)
sid: resolved (fixed in 1.10.0-patch1+docs-1)
trixie: resolved (fixed in 1.10.0-patch1+docs-1)
GHSA
GHSA-gffv-475w-fvh4: In the HDF5 1
ghsa_unreviewed·2022-05-17
CVE-2016-4330 [HIGH] CWE-119 GHSA-gffv-475w-fvh4: In the HDF5 1
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
OSV
CVE-2016-4330: In the HDF5 1
osv·2016-11-18·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330: In the HDF5 1
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
OSV
perl vulnerabilities
osv·2016-03-02·CVSS 7.5
CVE-2013-7422 perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2016-4330 hdf5: H5T_ARRAY heap buffer overflow
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 hdf5: H5T_ARRAY heap buffer overflow
CVE-2016-4330 hdf5: H5T_ARRAY heap buffer overflow
The vulnerability exists due to the library’s failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it. When reading elements from the file into this array, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
External References:
http://www.talosintelligence.com/reports/TALOS-2016-0176/
Discussion:
Created hdf5 tracking bugs for this issue:
Affects: fedora-all [bug 1397715]
Affects: epel-all [bug 1397716]
---
Created hdf5 tracking bugs for this issue:
Affects: openshift-1 [bug 1470478]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/secur
Bugzilla
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Talos
Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
blogs_talos·2016-11-18·CVSS 8.6
[HIGH] Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
These vulnerabilities were discovered by the Talos Vulnerability Development Team.
Today, Talos is disclosing the discovery of four vulnerabilities which have been identified in HDF5. HDF5 is a file format that is designed to be used for storage and organization of large amounts of scientific data and is used to exchange data between applications. In the GIS industry it used via libraries such as GDAL, OGR, or as part of software like ArcGIS. HDF5 is maintained by The HDF Group, a non-profit organization which Talos coordinated with to ensure these vulnerabilities were disclosed in a responsible manner. These vulnerabilities were patched in the HDF5 1.8.18 release.
The following is a list of the vulnerabilities that have been identified and patched:
- CVE-2016-4330 (TALOS-2016-0176) - H
Talos
Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
blogs_talos·2016-11-18·CVSS 8.6
[HIGH] Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
## Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
These vulnerabilities were discovered by the Talos Vulnerability Development Team.
Today, Talos is disclosing the discovery of four vulnerabilities which have been identified in HDF5. HDF5 is a file format that is designed to be used for storage and organization of large amounts of scientific data and is used to exchange data between applications. In the GIS industry it used via libraries such as GDAL, OGR, or as part of software like ArcGIS. HDF5 is maintained by The HDF Group, a non-profit organization which Talos coordinated with to ensure these vulnerabilities were disclosed in a responsible manner. These vulnerabilities were patched in the HDF5 1.8.18 release.
The following is a list of the vulnerab
http://www.debian.org/security/2016/dsa-3727http://www.securityfocus.com/bid/94414http://www.talosintelligence.com/reports/TALOS-2016-0176/https://security.gentoo.org/glsa/201701-13http://www.debian.org/security/2016/dsa-3727http://www.securityfocus.com/bid/94414http://www.talosintelligence.com/reports/TALOS-2016-0176/https://security.gentoo.org/glsa/201701-13
2016-11-18
Published