A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O_chunkprotect of the file /src/H5Ochunk.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
{
"binaries": [
{
"binary_name": "hdf5-helpers",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "hdf5-tools",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-103",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-cpp-103",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-dev",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-java",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-jni",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-mpi-dev",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-mpich-103",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-mpich-dev",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-openmpi-103",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
},
{
"binary_name": "libhdf5-openmpi-dev",
"binary_version": "1.10.4+repack-11ubuntu1+esm1"
}
],
"priority_reason": "Upstream rates this as being low severity"
}
{
"binaries": [
{
"binary_name": "hdf5-helpers",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "hdf5-tools",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-103",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-103-1",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-cpp-103",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-cpp-103-1",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-dev",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-fortran-102",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-hl-100",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-hl-cpp-100",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-hl-fortran-100",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-java",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-jni",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpi-dev",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpich-103",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpich-103-1",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpich-cpp-103-1",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpich-dev",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpich-fortran-102",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpich-hl-100",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpich-hl-cpp-100",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-mpich-hl-fortran-100",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-openmpi-103",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-openmpi-103-1",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-openmpi-cpp-103-1",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-openmpi-dev",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-openmpi-fortran-102",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-openmpi-hl-100",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-openmpi-hl-cpp-100",
"binary_version": "1.10.7+repack-4ubuntu2"
},
{
"binary_name": "libhdf5-openmpi-hl-fortran-100",
"binary_version": "1.10.7+repack-4ubuntu2"
}
],
"priority_reason": "Upstream rates this as being low severity"
}
{
"binaries": [
{
"binary_name": "hdf5-helpers",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "hdf5-tools",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-103-1t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-cpp-103-1t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-dev",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-fortran-102t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-hl-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-hl-cpp-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-hl-fortran-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-java",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-jni",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-mpi-dev",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-mpich-103-1t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-mpich-cpp-103-1t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-mpich-dev",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-mpich-fortran-102t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-mpich-hl-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-mpich-hl-cpp-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-mpich-hl-fortran-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-openmpi-103-1t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-openmpi-cpp-103-1t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-openmpi-dev",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-openmpi-fortran-102t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-openmpi-hl-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-openmpi-hl-cpp-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
},
{
"binary_name": "libhdf5-openmpi-hl-fortran-100t64",
"binary_version": "1.10.10+repack-3.1ubuntu4"
}
],
"priority_reason": "Upstream rates this as being low severity"
}
{
"binaries": [
{
"binary_name": "hdf5-helpers",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "hdf5-tools",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-cpp-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-dev",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-fortran-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-hl-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-hl-cpp-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-hl-fortran-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-java",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-jni",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-mpi-dev",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-mpich-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-mpich-cpp-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-mpich-dev",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-mpich-fortran-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-mpich-hl-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-mpich-hl-cpp-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-mpich-hl-fortran-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-openmpi-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-openmpi-cpp-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-openmpi-dev",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-openmpi-fortran-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-openmpi-hl-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-openmpi-hl-cpp-310",
"binary_version": "1.14.5+repack-3build1"
},
{
"binary_name": "libhdf5-openmpi-hl-fortran-310",
"binary_version": "1.14.5+repack-3build1"
}
],
"priority_reason": "Upstream rates this as being low severity"
}