Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2022-25942
HistoryAug 22, 2022 - 7:15 p.m.

CVE-2022-25942

2022-08-2219:15:09
Debian Security Bug Tracker
security-tracker.debian.org
11
out-of-bounds read
gif file
code execution
hdf5 group
libhdf5
vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

36.3%

An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

OSVersionArchitecturePackageVersionFilename
Debian12allhdf5<= 1.10.8+repack1-1hdf5_1.10.8+repack1-1_all.deb
Debian11allhdf5<= 1.10.6+repack-4+deb11u1hdf5_1.10.6+repack-4+deb11u1_all.deb
Debian999allhdf5<= 1.10.10+repack-4hdf5_1.10.10+repack-4_all.deb
Debian13allhdf5<= 1.10.10+repack-4hdf5_1.10.10+repack-4_all.deb

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

36.3%