CVE-2016-4331
published 2016-11-18CVE-2016-4331: When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of…
PriorityP339high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.76%
51.2th percentile
When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | < hdf5 1.10.0-patch1+docs-1 (bookworm) | hdf5 1.10.0-patch1+docs-1 (bookworm) |
| hdfgroup | hdf5 | — | — |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hhr-jhmc-r3cj: When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1
ghsa_unreviewed·2022-05-17
CVE-2016-4331 [HIGH] CWE-787 GHSA-4hhr-jhmc-r3cj: When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1
When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
OSV
CVE-2016-4331: When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1
osv·2016-11-18·CVSS 8.6
CVE-2016-4331 [HIGH] CVE-2016-4331: When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1
When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
Red Hat
hdf5: H5Z_NBIT heap buffer overflow
vendor_redhat·2016-11-15·CVSS 8.6
CVE-2016-4331 [HIGH] CWE-122 hdf5: H5Z_NBIT heap buffer overflow
hdf5: H5Z_NBIT heap buffer overflow
When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
Multiple heap overflows were found in HDF5. These issues could be used to gain code execution in any program that exposes the affected functions to untrusted input. While HDF5 is shipped as a dependency, no Red Hat products are known to expose these issues in any supported use case at this time.
Package: hdf5 (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Package: hdf5 (Red Hat OpenShift Enterprise 2) - Will not fix
Package: hdf5 (Red Hat OpenStack Platform 10 (Newton)) - Will not fix
Package: hdf5 (Red Hat OpenStack Platfor
Debian
CVE-2016-4331: hdf5 - When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5...
vendor_debian·2016·CVSS 8.6
CVE-2016-4331 [HIGH] CVE-2016-4331: hdf5 - When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5...
When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 1.10.0-patch1+docs-1)
bullseye: resolved (fixed in 1.10.0-patch1+docs-1)
forky: resolved (fixed in 1.10.0-patch1+docs-1)
sid: resolved (fixed in 1.10.0-patch1+docs-1)
trixie: resolved (fixed in 1.10.0-patch1+docs-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2016-4331 hdf5: H5Z_NBIT heap buffer overflow
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4331 [HIGH] CVE-2016-4331 hdf5: H5Z_NBIT heap buffer overflow
CVE-2016-4331 hdf5: H5Z_NBIT heap buffer overflow
The vulnerability exists when the library is decoding data out of a dataset encoded with the H5Z_NBIT decoding. When calculating the precision that a BCD number is encoded as, the library will fail to ensure that the precision is within the bounds of the size. Due to this, the library will calculate an index outside the bounds of the space allocated for the BCD number. Whilst decoding this data, the library will then write outside the bounds of the buffer leading to a heap-based buffer overflow. This can lead to code execution under the context of the application using the library.
External References:
http://www.talosintelligence.com/reports/TALOS-2016-0177/
Discussion:
Created hdf5 tracking bugs for this issue:
Affects: fedora-all [
Bugzilla
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Talos
Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
blogs_talos·2016-11-18·CVSS 8.6
[HIGH] Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
These vulnerabilities were discovered by the Talos Vulnerability Development Team.
Today, Talos is disclosing the discovery of four vulnerabilities which have been identified in HDF5. HDF5 is a file format that is designed to be used for storage and organization of large amounts of scientific data and is used to exchange data between applications. In the GIS industry it used via libraries such as GDAL, OGR, or as part of software like ArcGIS. HDF5 is maintained by The HDF Group, a non-profit organization which Talos coordinated with to ensure these vulnerabilities were disclosed in a responsible manner. These vulnerabilities were patched in the HDF5 1.8.18 release.
The following is a list of the vulnerabilities that have been identified and patched:
- CVE-2016-4330 (TALOS-2016-0176) - H
Talos
Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
blogs_talos·2016-11-18·CVSS 8.6
[HIGH] Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
## Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
These vulnerabilities were discovered by the Talos Vulnerability Development Team.
Today, Talos is disclosing the discovery of four vulnerabilities which have been identified in HDF5. HDF5 is a file format that is designed to be used for storage and organization of large amounts of scientific data and is used to exchange data between applications. In the GIS industry it used via libraries such as GDAL, OGR, or as part of software like ArcGIS. HDF5 is maintained by The HDF Group, a non-profit organization which Talos coordinated with to ensure these vulnerabilities were disclosed in a responsible manner. These vulnerabilities were patched in the HDF5 1.8.18 release.
The following is a list of the vulnerab
http://www.debian.org/security/2016/dsa-3727http://www.securityfocus.com/bid/94411http://www.talosintelligence.com/reports/TALOS-2016-0177/https://security.gentoo.org/glsa/201701-13http://www.debian.org/security/2016/dsa-3727http://www.securityfocus.com/bid/94411http://www.talosintelligence.com/reports/TALOS-2016-0177/https://security.gentoo.org/glsa/201701-13
2016-11-18
Published