CVE-2017-17505NULL Pointer Dereference in Hdf5

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 37.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 17

Description

In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_decode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/hdf5< hdf5 1.10.4+repack-1 (bookworm)
Debianhdfgroup/hdf5< 1.10.4+repack-1+3
NVDhdfgroup/hdf51.10.1

🔴Vulnerability Details

2
GHSA
GHSA-v33c-vr3g-mwh2: In HDF5 12022-05-17
OSV
CVE-2017-17505: In HDF5 12017-12-11

📋Vendor Advisories

3
Ubuntu
HDF5 vulnerabilities2021-03-15
Red Hat
hdf5: NULL pointer dereference in the H5O_pline_decode function2017-12-08
Debian
CVE-2017-17505: hdf5 - In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_de...2017

💬Community

3
Bugzilla
CVE-2017-17505 hdf5: NULL pointer dereference in the H5O_pline_decode function2017-12-12
Bugzilla
CVE-2017-17505 CVE-2017-17506 CVE-2017-17507 CVE-2017-17508 CVE-2017-17509 hdf5: various flaws [fedora-all]2017-12-12
Bugzilla
CVE-2017-17505 CVE-2017-17506 CVE-2017-17507 CVE-2017-17508 CVE-2017-17509 hdf5: various flaws [epel-all]2017-12-12