Description HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Exploitability: 3.9 | Impact: 5.2 Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: High
Affected Packages7 packages Show 2 more packages
🔴 Vulnerability Details2 GHSA GHSA-8g42-4xgf-8mcj: HDF5 Library through 1 ↗ 2024-05-14 ▶ OSV CVE-2024-32622: HDF5 Library through 1 ↗ 2024-05-14 ▶
📋 Vendor Advisories3 Microsoft HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c). ↗ 2024-05-14 ▶ Red Hat hdf5: multiple CVEs ↗ 2024-05-10 ▶ Debian CVE-2024-32622: hdf5 - HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_... ↗ 2024 ▶