HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hdfgroup
Hdfgroup hdf5 |
|
CPEs | cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hdfgroup
Hdfgroup hdf5 |
|
Metrics |
ssvc
|
Tue, 20 Aug 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-122 | |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-05-09T16:43:49.875Z
Updated: 2025-02-13T15:52:25.069Z
Reserved: 2024-04-16T00:00:00.000Z
Link: CVE-2024-32617

Updated: 2024-08-02T02:13:40.225Z

Status : Awaiting Analysis
Published: 2024-05-14T15:36:46.893
Modified: 2024-11-21T09:15:19.697
Link: CVE-2024-32617
