CVE-2024-32606
published 2024-05-14CVE-2024-32606: HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from…
PriorityP422medium5.7CVSS 3.1
AVLACHPRNUINSUCNILAH
EPSS
0.23%
13.4th percentile
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | < hdf5 1.14.5+repack-1 (forky) | hdf5 1.14.5+repack-1 (forky) |
| hdfgroup | hdf5 | < 1.14.4 | 1.14.4 |
| hdfgroup | hdf5 | >= 0 < 1.14.5+repack-1 | 1.14.5+repack-1 |
| hdfgroup | hdf5 | >= 0 < 1.14.5+repack-1 | 1.14.5+repack-1 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
osv5.7MEDIUM
vendor_debian5.7LOW
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hdf5: multiple CVEs
vendor_redhat·2024-05-10·CVSS 5.7
CVE-2024-32606 [MEDIUM] hdf5: multiple CVEs
hdf5: multiple CVEs
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
Package: hdf5 (Red Hat OpenStack Platform 16.1) - Out of support scope
Debian
CVE-2024-32606: hdf5 - HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h...
vendor_debian·2024·CVSS 5.7
CVE-2024-32606 [MEDIUM] CVE-2024-32606: hdf5 - HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h...
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
GHSA
GHSA-m29j-f39x-2r24: HDF5 Library through 1
ghsa_unreviewed·2024-05-14
CVE-2024-32606 [MEDIUM] CWE-908 GHSA-m29j-f39x-2r24: HDF5 Library through 1
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
OSV
CVE-2024-32606: HDF5 Library through 1
osv·2024-05-14·CVSS 5.7
CVE-2024-32606 [MEDIUM] CVE-2024-32606: HDF5 Library through 1
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
No detection rules found.
No public exploits indexed.
2024-05-14
Published