In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "hdf5-helpers",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "hdf5-tools",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "libhdf5-7",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "libhdf5-dev",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "libhdf5-mpi-dev",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "libhdf5-mpich2-7",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "libhdf5-mpich2-dev",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "libhdf5-openmpi-7",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "libhdf5-openmpi-dev",
"binary_version": "1.8.11-5ubuntu7.1"
},
{
"binary_name": "libhdf5-serial-dev",
"binary_version": "1.8.11-5ubuntu7.1"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "hdf5-helpers",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "hdf5-tools",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-10",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-cpp-11",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-dev",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-mpi-dev",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-mpich-10",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-mpich-dev",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-openmpi-10",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-openmpi-dev",
"binary_version": "1.8.16+docs-4ubuntu1.1"
},
{
"binary_name": "libhdf5-serial-dev",
"binary_version": "1.8.16+docs-4ubuntu1.1"
}
]
}