cbcvebase.
CVE-2016-4332
published 2016-11-18

CVE-2016-4332: The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure…

PriorityP337high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.81%
52.7th percentile
The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianhdf5< hdf5 1.10.0-patch1+docs-1 (bookworm)hdf5 1.10.0-patch1+docs-1 (bookworm)
hdfgrouphdf5
hdfgrouphdf5>= 0 < 1.10.0-patch1+docs-11.10.0-patch1+docs-1
hdfgrouphdf5>= 0 < 1.10.0-patch1+docs-11.10.0-patch1+docs-1
hdfgrouphdf5>= 0 < 1.10.0-patch1+docs-11.10.0-patch1+docs-1
hdfgrouphdf5>= 0 < 1.10.0-patch1+docs-11.10.0-patch1+docs-1

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.