HIGH
hdf5: Heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c
Published Jul 20, 2018
8.8
HIGHCVSS 3.0
EPSS 1.56%
Description
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
hdf5
Will not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
hdf5
Will not fix
Red Hat OpenStack Platform 10 (Newton)
hdf5
Fix deferred
Red Hat OpenStack Platform 12 (Pike)
hdf5
Affected
Red Hat OpenStack Platform 13 (Queens)
hdf5
Fix deferred
Red Hat OpenStack Platform 14 (Rocky)
hdf5
Fix deferred
Red Hat OpenStack Platform 8 (Liberty)
hdf5
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
hdf5
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | hdf5 | Will not fix | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | hdf5 | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | hdf5 | Fix deferred | n/a |
| Red Hat OpenStack Platform 12 (Pike) | hdf5 | Affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | hdf5 | Fix deferred | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | hdf5 | Fix deferred | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | hdf5 | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | hdf5 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://access.redhat.com/security/cve/CVE-2018-14460 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1607608 Issue Tracking
- https://github.com/TeamSeri0us/pocs/blob/master/hdf5/README3.md x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-14460
- https://www.cve.org/CVERecord?id=CVE-2018-14460
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-14460 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1607608 | Issue Tracking | |
| https://github.com/TeamSeri0us/pocs/blob/master/hdf5/README3.md | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-14460 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-14460 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 20, 2018
Updated Aug 5, 2024
Reserved Jul 20, 2018
Link CVE-2018-14460
CISA Vulnrichment
Updated n/a