CVE-2016-4333

The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hdfgroup:hdf5:1.8.16:*:*:*:*:*:*:*

History

21 Nov 2024, 02:51

Type Values Removed Values Added
References () http://www.debian.org/security/2016/dsa-3727 - () http://www.debian.org/security/2016/dsa-3727 -
References () http://www.securityfocus.com/bid/94416 - () http://www.securityfocus.com/bid/94416 -
References () http://www.talosintelligence.com/reports/TALOS-2016-0179/ - Exploit, Technical Description, Third Party Advisory () http://www.talosintelligence.com/reports/TALOS-2016-0179/ - Exploit, Technical Description, Third Party Advisory
References () https://security.gentoo.org/glsa/201701-13 - () https://security.gentoo.org/glsa/201701-13 -

Information

Published : 2016-11-18 20:59

Updated : 2024-11-21 02:51


NVD link : CVE-2016-4333

Mitre link : CVE-2016-4333

CVE.ORG link : CVE-2016-4333


JSON object : View

Products Affected

hdfgroup

  • hdf5
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer