CVE-2016-4333
published 2016-11-18CVE-2016-4333: The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value…
PriorityP434high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.61%
45.3th percentile
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | < hdf5 1.10.0-patch1+docs-1 (bookworm) | hdf5 1.10.0-patch1+docs-1 (bookworm) |
| hdfgroup | hdf5 | — | — |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
| hdfgroup | hdf5 | >= 0 < 1.10.0-patch1+docs-1 | 1.10.0-patch1+docs-1 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hvm6-p25j-5hjf: The HDF5 1
ghsa_unreviewed·2022-05-17
CVE-2016-4333 [HIGH] CWE-119 GHSA-hvm6-p25j-5hjf: The HDF5 1
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
OSV
CVE-2016-4333: The HDF5 1
osv·2016-11-18·CVSS 8.6
CVE-2016-4333 [HIGH] CVE-2016-4333: The HDF5 1
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
Red Hat
hdf5: H5T_COMPOUND heap buffer overflow
vendor_redhat·2016-11-15·CVSS 8.6
CVE-2016-4333 [HIGH] CWE-122 hdf5: H5T_COMPOUND heap buffer overflow
hdf5: H5T_COMPOUND heap buffer overflow
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
Multiple heap overflows were found in HDF5. These issues could be used to gain code execution in any program that exposes the affected functions to untrusted input. While HDF5 is shipped as a dependency, no Red Hat products are known to expose these issues in any supported use case at this time.
Package: hdf5 (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Package: hdf5 (Red Hat OpenShift Enterprise 2) - Wil
Debian
CVE-2016-4333: hdf5 - The HDF5 1.8.16 library allocating space for the array using a value from the fi...
vendor_debian·2016·CVSS 8.6
CVE-2016-4333 [HIGH] CVE-2016-4333: hdf5 - The HDF5 1.8.16 library allocating space for the array using a value from the fi...
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
Scope: local
bookworm: resolved (fixed in 1.10.0-patch1+docs-1)
bullseye: resolved (fixed in 1.10.0-patch1+docs-1)
forky: resolved (fixed in 1.10.0-patch1+docs-1)
sid: resolved (fixed in 1.10.0-patch1+docs-1)
trixie: resolved (fixed in 1.10.0-patch1+docs-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4330 [HIGH] CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
CVE-2016-4330 CVE-2016-4331 CVE-2016-4332 CVE-2016-4333 hdf5: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2016-4333 hdf5: H5T_COMPOUND heap buffer overflow
bugzilla·2016-11-23·CVSS 8.6
CVE-2016-4333 [HIGH] CVE-2016-4333 hdf5: H5T_COMPOUND heap buffer overflow
CVE-2016-4333 hdf5: H5T_COMPOUND heap buffer overflow
The vulnerability exists due to the library allocating space for the array using a value from the file, and then within the loop for initializing said array allowing a value within the file to modify the loop’s terminator. Due to this, an aggressor can cause the loop’s index to point outside the bounds of the array when initializing it. This is a heap-based buffer overflow, and can lead to code execution under the context of the application using the library.
External References:
http://www.talosintelligence.com/reports/TALOS-2016-0179/
Discussion:
Created hdf5 tracking bugs for this issue:
Affects: fedora-all [bug 1397715]
Affects: epel-all [bug 1397716]
---
Created hdf5 tracking bugs for this issue:
Affects: openshift-1 [bug
Talos
Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
blogs_talos·2016-11-18·CVSS 8.6
[HIGH] Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
These vulnerabilities were discovered by the Talos Vulnerability Development Team.
Today, Talos is disclosing the discovery of four vulnerabilities which have been identified in HDF5. HDF5 is a file format that is designed to be used for storage and organization of large amounts of scientific data and is used to exchange data between applications. In the GIS industry it used via libraries such as GDAL, OGR, or as part of software like ArcGIS. HDF5 is maintained by The HDF Group, a non-profit organization which Talos coordinated with to ensure these vulnerabilities were disclosed in a responsible manner. These vulnerabilities were patched in the HDF5 1.8.18 release.
The following is a list of the vulnerabilities that have been identified and patched:
- CVE-2016-4330 (TALOS-2016-0176) - H
Talos
Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
blogs_talos·2016-11-18·CVSS 8.6
[HIGH] Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
## Vulnerability Spotlight: Multiple File Parsing Bugs in HDF5 File Library Patched
These vulnerabilities were discovered by the Talos Vulnerability Development Team.
Today, Talos is disclosing the discovery of four vulnerabilities which have been identified in HDF5. HDF5 is a file format that is designed to be used for storage and organization of large amounts of scientific data and is used to exchange data between applications. In the GIS industry it used via libraries such as GDAL, OGR, or as part of software like ArcGIS. HDF5 is maintained by The HDF Group, a non-profit organization which Talos coordinated with to ensure these vulnerabilities were disclosed in a responsible manner. These vulnerabilities were patched in the HDF5 1.8.18 release.
The following is a list of the vulnerab
http://www.debian.org/security/2016/dsa-3727http://www.securityfocus.com/bid/94416http://www.talosintelligence.com/reports/TALOS-2016-0179/https://security.gentoo.org/glsa/201701-13http://www.debian.org/security/2016/dsa-3727http://www.securityfocus.com/bid/94416http://www.talosintelligence.com/reports/TALOS-2016-0179/https://security.gentoo.org/glsa/201701-13
2016-11-18
Published