Debian Hdf5 vulnerabilities
77 known vulnerabilities affecting debian/hdf5.
Total CVEs
77
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM3LOW68
Vulnerabilities
Page 2 of 4
CVE-2024-32618P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-32618 [HIGH] CVE-2024-32618: hdf5 - HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_na...
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2024-32619P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-32619 [HIGH] CVE-2024-32619: hdf5 - HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_re...
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2018-16438P3LOWCVSS 8.8fixed in hdf5 1.14.5+repack-1 (forky)2018
CVE-2018-16438 [HIGH] CVE-2018-16438: hdf5 - An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bound...
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2018-11206P3LOWCVSS 8.1fixed in hdf5 1.10.8+repack-1 (bookworm)2018
CVE-2018-11206 [HIGH] CVE-2018-11206: hdf5 - An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_dec...
An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
Scope: local
bookworm: resolved (fixed in 1.10.8+repack-1)
bullseye: open
forky: resolved (fixed in 1.10.8+repack-1)
sid: resolved (fixed in 1.10.8+repack-1)
trixie:
debian
CVE-2024-32617P3LOWCVSS 8.8fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-32617 [HIGH] CVE-2024-32617: hdf5 - HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the...
HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2016-4332P3HIGHCVSS 8.6fixed in hdf5 1.10.0-patch1+docs-1 (bookworm)2016
CVE-2016-4332 [HIGH] CVE-2016-4332: hdf5 - The library's failure to check if certain message types support a particular fla...
The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.
Scope: local
b
debian
CVE-2021-37501P3LOWCVSS 7.5fixed in hdf5 1.14.5+repack-1 (forky)2021
CVE-2021-37501 [HIGH] CVE-2021-37501: hdf5 - Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allo...
Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2017-17509P3HIGHCVSS 8.8fixed in hdf5 1.10.4+repack-1 (bookworm)2017
CVE-2017-17509 [HIGH] CVE-2017-17509: hdf5 - In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5...
In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.
Scope: local
bookworm: resolved (fixed in 1.10.4+repack-1)
bullseye: resolved (fixed in 1.10.4+repack-1)
forky: resolved (fixed in 1.10.
debian
CVE-2016-4330P3HIGHCVSS 8.6fixed in hdf5 1.10.0-patch1+docs-1 (bookworm)2016
CVE-2016-4330 [HIGH] CVE-2016-4330: hdf5 - In the HDF5 1.8.16 library's failure to check if the number of dimensions for an...
In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 1.10.0-patch1+docs-1)
bullseye: resolved (fixed in 1.10.0-patch1+docs-1)
forky: res
debian
CVE-2022-25972P3LOWCVSS 7.8fixed in hdf5 1.10.10+repack-1 (forky)2022
CVE-2022-25972 [HIGH] CVE-2022-25972: hdf5 - An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 ...
An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.10.10+repack-1)
sid: resolved (fixed in 1.10.10+repack-1)
trixie: res
debian
CVE-2022-25942P3LOWCVSS 7.8fixed in hdf5 1.10.10+repack-1 (forky)2022
CVE-2022-25942 [HIGH] CVE-2022-25942: hdf5 - An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 G...
An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.10.10+repack-1)
sid: resolved (fixed in 1.10.10+repack-1)
trixie: reso
debian
CVE-2024-29165P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-29165 [HIGH] CVE-2024-29165: hdf5 - HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, result...
HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2024-29158P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-29158 [HIGH] CVE-2024-29158: hdf5 - HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulti...
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2024-29162P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-29162 [HIGH] CVE-2024-29162: hdf5 - HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read,...
HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2018-11205P3HIGHCVSS 8.1fixed in hdf5 1.14.5+repack-1 (forky)2018
CVE-2018-11205 [HIGH] CVE-2018-11205: hdf5 - A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1...
A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2024-32616P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-32616 [HIGH] CVE-2024-32616: hdf5 - HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype...
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2024-32612P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-32612 [HIGH] CVE-2024-32612: hdf5 - HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_d...
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+
debian
CVE-2024-29163P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-29163 [HIGH] CVE-2024-29163: hdf5 - HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting ...
HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2024-29160P3LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-29160 [HIGH] CVE-2024-29160: hdf5 - HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserial...
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2016-4333P4HIGHCVSS 8.6fixed in hdf5 1.10.0-patch1+docs-1 (bookworm)2016
CVE-2016-4333 [HIGH] CVE-2016-4333: hdf5 - The HDF5 1.8.16 library allocating space for the array using a value from the fi...
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
Scope: local
bookworm: resolved (fixed in 1.10.0-p
debian