Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2018-14031
HistoryOct 03, 2022 - 4:22 p.m.

CVE-2018-14031

2022-10-0316:22:27
Debian Security Bug Tracker
security-tracker.debian.org
7
hdf5 library
heap-based
buffer over-read
h5t_copy function
unix

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.3%

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c.

OSVersionArchitecturePackageVersionFilename
Debian12allhdf5<= 1.10.8+repack1-1hdf5_1.10.8+repack1-1_all.deb
Debian11allhdf5<= 1.10.6+repack-4+deb11u1hdf5_1.10.6+repack-4+deb11u1_all.deb
Debian999allhdf5<= 1.10.10+repack-3.3hdf5_1.10.10+repack-3.3_all.deb
Debian13allhdf5<= 1.10.10+repack-3.3hdf5_1.10.10+repack-3.3_all.deb

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.3%