CVE-2021-37501Out-of-bounds Write in Hdf5

Severity
7.5HIGHNVD
EPSS
0.1%
top 74.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3
Latest updateApr 27

Description

Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages8 packages

Debianhdfgroup/hdf5< 1.14.5+repack-1+1
NVDhdfgroup/hdf51.12.01.13.0
debiandebian/hdf5< hdf5 1.14.5+repack-1 (forky)

🔴Vulnerability Details

2
GHSA
GHSA-rfgw-5vq3-wrjf: Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 12023-02-03
OSV
CVE-2021-37501: Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 12023-02-03

📋Vendor Advisories

3
Red Hat
hdf5: heap buffer overread2023-04-27
Microsoft
Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.2023-02-14
Debian
CVE-2021-37501: hdf5 - Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allo...2021