CVE-2016-4332
published 2016-11-18CVE-2016-4332: The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure…
PriorityP337high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.81%
52.7th percentile
The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | < hdf5 1.10.0-patch1+docs-1 (bookworm) | hdf5 1.10.0-patch1+docs-1 (bookworm) |
| hdfgroup | hdf5 | — | — |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-349c-4hpx-25pr: The library's failure to check if certain message types support a particular flag, the HDF5 1
ghsa_unreviewed·2022-05-17
CVE-2016-4332 [HIGH] CWE-20 GHSA-349c-4hpx-25pr: The library's failure to check if certain message types support a particular flag, the HDF5 1
The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.
OSV
CVE-2016-4332: The library's failure to check if certain message types support a particular flag, the HDF5 1
osv·2016-11-18·CVSS 8.6
CVE-2016-4332 [HIGH] CVE-2016-4332: The library's failure to check if certain message types support a particular flag, the HDF5 1
The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.
Red Hat
hdf5: Shareable message type out-of-bounds write
vendor_redhat·2016-11-15·CVSS 8.6
CVE-2016-4332 [HIGH] CWE-787 hdf5: Shareable message type out-of-bounds write
hdf5: Shareable message type out-of-bounds write
The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.
Multiple heap overflows were found in HDF5. These issues could be used to gain code execution in any program that exposes the affected functions to untrusted input. While HDF5 is shipped as a dependency, no Red Hat products are known to expose these issues in any supported use case at this time.
Package: hdf5 (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Package
Debian
CVE-2016-4332: hdf5 - The library's failure to check if certain message types support a particular fla...
vendor_debian·2016·CVSS 8.6
CVE-2016-4332 [HIGH] CVE-2016-4332: hdf5 - The library's failure to check if certain message types support a particular fla...
The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.
Scope: local
bookworm: resolved (fixed in 1.10.0-patch1+docs-1)
bullseye: resolved (fixed in 1.10.0-patch1+docs-1)
forky: resolved (fixed in 1.10.0-patch1+docs-1)
sid: resolved (fixed in 1.10.0-patch1+docs-1)
trixie: resolved (fixed in 1.10.0-patch1+docs-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2016-4332 hdf5: Shareable message type out-of-bounds write
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4332 [HIGH] CVE-2016-4332 hdf5: Shareable message type out-of-bounds write
CVE-2016-4332 hdf5: Shareable message type out-of-bounds write
The vulnerability exists due to the library’s failure to check if certain message types support a particular flag. When this flag is set, the library will cast the structure to an alternative structure and then assign to fields that aren’t supported by the message type. Due to the message type not being able to support this flag, the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.
External References:
http://www.talosintelligence.com/reports/TALOS-2016-0178/
Discussion:
Created hdf5 tracking bugs for this issue:
Affects: fedora-all [bug 1397715]
Affects: epel-all [bug 1397716]
---
Created hdf5 tracking bugs for this issue:
Affects: openshift-1
Talos
Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
blogs_talos·2016-11-18·CVSS 8.6
[HIGH] Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
These vulnerabilities were discovered by the Talos Vulnerability Development Team.
Today, Talos is disclosing the discovery of four vulnerabilities which have been identified in HDF5. HDF5 is a file format that is designed to be used for storage and organization of large amounts of scientific data and is used to exchange data between applications. In the GIS industry it used via libraries such as GDAL, OGR, or as part of software like ArcGIS. HDF5 is maintained by The HDF Group, a non-profit organization which Talos coordinated with to ensure these vulnerabilities were disclosed in a responsible manner. These vulnerabilities were patched in the HDF5 1.8.18 release.
The following is a list of the vulnerabilities that have been identified and patched:
- CVE-2016-4330 (TALOS-2016-0176) - H
Talos
Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
blogs_talos·2016-11-18·CVSS 8.6
[HIGH] Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
## Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
These vulnerabilities were discovered by the Talos Vulnerability Development Team.
Today, Talos is disclosing the discovery of four vulnerabilities which have been identified in HDF5. HDF5 is a file format that is designed to be used for storage and organization of large amounts of scientific data and is used to exchange data between applications. In the GIS industry it used via libraries such as GDAL, OGR, or as part of software like ArcGIS. HDF5 is maintained by The HDF Group, a non-profit organization which Talos coordinated with to ensure these vulnerabilities were disclosed in a responsible manner. These vulnerabilities were patched in the HDF5 1.8.18 release.
The following is a list of the vulnerab
http://www.debian.org/security/2016/dsa-3727http://www.securityfocus.com/bid/94417http://www.talosintelligence.com/reports/TALOS-2016-0178/https://security.gentoo.org/glsa/201701-13http://www.debian.org/security/2016/dsa-3727http://www.securityfocus.com/bid/94417http://www.talosintelligence.com/reports/TALOS-2016-0178/https://security.gentoo.org/glsa/201701-13
2016-11-18
Published