Back

MEDIUM

hdf5: Divide-by-zero in the H5T_set_loc function

Published Dec 11, 2017

Description

In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5T_set_loc in the H5T.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Whilst the package shipped with Red Hat OpenStack contains the vulnerable code, the packages that use HDF5 do not expose the vulnerable functionality.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 11, 2017
Updated Sep 16, 2024
Reserved Dec 10, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 8, 2017