Debian Hdf5 vulnerabilities
77 known vulnerabilities affecting debian/hdf5.
Total CVEs
77
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM3LOW68
Vulnerabilities
Page 3 of 4
CVE-2018-13870P4LOWCVSS 9.8fixed in hdf5 1.10.7+repack-1 (bookworm)2018
CVE-2018-13870 [CRITICAL] CVE-2018-13870: hdf5 - An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based bu...
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_link_decode in H5Olink.c.
Scope: local
bookworm: resolved (fixed in 1.10.7+repack-1)
bullseye: open
forky: resolved (fixed in 1.10.7+repack-1)
sid: resolved (fixed in 1.10.7+repack-1)
trixie: resolved (fixed in 1.10.7+repack-1)
debian
CVE-2022-26061P4LOWCVSS 7.8fixed in hdf5 1.10.10+repack-1 (forky)2022
CVE-2022-26061 [HIGH] CVE-2022-26061: hdf5 - A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of...
A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.10.10+repack-1)
sid: resolved (fixed in 1.10.10+repack-1)
trixi
debian
CVE-2024-32613P4LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-32613 [HIGH] CVE-2024-32613: hdf5 - HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the functi...
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2024-32620P4LOWCVSS 7.4fixed in hdf5 1.14.5+repack-1 (forky)2024
CVE-2024-32620 [HIGH] CVE-2024-32620: hdf5 - HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_d...
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2018-14033P4LOWCVSS 8.8fixed in hdf5 1.14.5+repack-1 (forky)2018
CVE-2018-14033 [HIGH] CVE-2018-14033: hdf5 - An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based bu...
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_layout_decode in H5Olayout.c, related to HDmemcpy.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2018-14031P4LOWCVSS 8.8fixed in hdf5 1.14.5+repack-1 (forky)2018
CVE-2018-14031 [HIGH] CVE-2018-14031: hdf5 - An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based bu...
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
debian
CVE-2018-14460P4LOWCVSS 8.8fixed in hdf5 1.10.8+repack-1 (bookworm)2018
CVE-2018-14460 [HIGH] CVE-2018-14460: hdf5 - An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based bu...
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.
Scope: local
bookworm: resolved (fixed in 1.10.8+repack-1)
bullseye: open
forky: resolved (fixed in 1.10.8+repack-1)
sid: resolved (fixed in 1.10.8+repack-1)
trixie: resolved (fixed in 1.10.8+repack-1)
debian
CVE-2018-17233P4LOWCVSS 6.5fixed in hdf5 1.10.6+repack-2 (bookworm)2018
CVE-2018-17233 [MEDIUM] CVE-2018-17233: hdf5 - A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of ...
A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.10.6+repack-2)
bullseye: resolved (fix
debian
CVE-2018-17434P4LOWCVSS 6.5fixed in hdf5 1.10.6+repack-2 (bookworm)2018
CVE-2018-17434 [MEDIUM] CVE-2018-17434: hdf5 - A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c ...
A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.10.6+repack-2)
bullseye: resolved (fixed in 1.10.
debian
CVE-2018-17438P4LOWCVSS 6.5fixed in hdf5 1.10.6+repack-1 (bookworm)2018
CVE-2018-17438 [MEDIUM] CVE-2018-17438: hdf5 - A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the...
A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.10.6+repack-1)
bullseye: resolved (fixed in 1.10.6+repa
debian
CVE-2017-17508P4MEDIUMCVSS 6.5fixed in hdf5 1.10.4+repack-1 (bookworm)2017
CVE-2017-17508 [MEDIUM] CVE-2017-17508: hdf5 - In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5T_set_...
In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5T_set_loc in the H5T.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Scope: local
bookworm: resolved (fixed in 1.10.4+repack-1)
bullseye: resolved (fixed in 1.10.4+repack-1)
forky: resolved (fixed in 1.10.4+repack-1)
sid: resolved (fixed in 1.10.4+re
debian
CVE-2021-46244P4LOWCVSS 6.5fixed in hdf5 1.14.5+repack-1 (forky)2021
CVE-2021-46244 [MEDIUM] CVE-2021-46244: hdf5 - A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__co...
A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability causes an aritmetic exception, leading to a Denial of Service (DoS).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repac
debian
CVE-2018-11203P4LOWCVSS 6.5fixed in hdf5 1.10.4+repack-1 (bookworm)2018
CVE-2018-11203 [MEDIUM] CVE-2018-11203: hdf5 - A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the ...
A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.10.4+repack-1)
bullseye: resolved (fixed in 1.10.4+repack-1)
forky: resolved (fixed in 1.10.4+repack-1)
sid: resolved (fixed in 1.10.4+repack-1)
trixie: resolved (fixed i
debian
CVE-2018-17237P4LOWCVSS 6.5fixed in hdf5 1.10.6+repack-2 (bookworm)2018
CVE-2018-17237 [MEDIUM] CVE-2018-17237: hdf5 - A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk...
A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. This issue is different from CVE-2018-11207.
Scope: local
bookworm: resolved (fixed in 1.10.6+repack-2)
bullseye: resolved (fixed in 1.10.6+repack-2
debian
CVE-2018-17439P4LOWCVSS 6.5fixed in hdf5 1.14.5+repack-1 (forky)2018
CVE-2018-17439 [MEDIUM] CVE-2018-17439: hdf5 - An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based b...
An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixe
debian
CVE-2017-17506P4MEDIUMCVSS 6.5fixed in hdf5 1.10.4+repack-1 (bookworm)2017
CVE-2017-17506 [MEDIUM] CVE-2017-17506: hdf5 - In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5O...
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Scope: local
bookworm: resolved (fixed in 1.10.4+repack-1)
bullseye: resolved (fixed in 1.10.4+repack-1)
forky: resolved (fixed in 1.10.4+repack-1)
sid: resolved (fixed i
debian
CVE-2017-17505P4MEDIUMCVSS 6.5fixed in hdf5 1.10.4+repack-1 (bookworm)2017
CVE-2017-17505 [MEDIUM] CVE-2017-17505: hdf5 - In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_de...
In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_decode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
Scope: local
bookworm: resolved (fixed in 1.10.4+repack-1)
bullseye: resolved (fixed in 1.10.4+repack-1)
forky: resolved (fixed in 1.10.4+repack-1)
sid: resolved (fixed in 1.1
debian
CVE-2018-11207P4LOWCVSS 6.5fixed in hdf5 1.10.4+repack-1 (bookworm)2018
CVE-2018-11207 [MEDIUM] CVE-2018-11207: hdf5 - A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HD...
A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.10.4+repack-1)
bullseye: resolved (fixed in 1.10.4+repack-1)
forky: resolved (fixed in 1.10.4+repack-1)
sid: resolved (fixed in 1.10.4+repack-1)
trixie: resolved (fixed in 1.10
debian
CVE-2018-11202P4LOWCVSS 6.5fixed in hdf5 1.10.4+repack-1 (bookworm)2018
CVE-2018-11202 [MEDIUM] CVE-2018-11202: hdf5 - A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c ...
A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.10.4+repack-1)
bullseye: resolved (fixed in 1.10.4+repack-1)
forky: resolved (fixed in 1.10.4+repack-1)
sid: resolved (fixed in 1.10.4+repack-1)
trixie: resolved (
debian
CVE-2018-11204P4LOWCVSS 6.5fixed in hdf5 1.10.4+repack-1 (bookworm)2018
CVE-2018-11204 [MEDIUM] CVE-2018-11204: hdf5 - A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache....
A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.10.4+repack-1)
bullseye: resolved (fixed in 1.10.4+repack-1)
forky: resolved (fixed in 1.10.4+repack-1)
sid: resolved (fixed in 1.10.4+repack-1)
trixie: resolved
debian