Description
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. Affected by this issue is the function H5O__mtime_new_encode of the file src/H5Omtime.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Eine problematische Schwachstelle wurde in HDF5 1.14.6 entdeckt. Betroffen davon ist die Funktion H5O__mtime_new_encode der Datei src/H5Omtime.c. Durch das Beeinflussen mit unbekannten Daten kann eine heap-based buffer overflow-Schwachstelle ausgenutzt werden. Der Angriff muss lokal passieren. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Timeline
| 2025-06-26: | Advisory disclosed |
| 2025-06-26: | VulDB entry created |
| 2025-06-26: | VulDB entry last update |
Credits
JJLeo (VulDB User)
References
github.com/HDFGroup/hdf5/issues/5549
vuldb.com/?id.314048 (VDB-314048 | HDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflow)
vuldb.com/?ctiid.314048 (VDB-314048 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.601017 (Submit #601017 | HDFGroup HDF5 hdf5 1.14.6 (commit 17c16b6) Heap-based Buffer Overflow)
github.com/HDFGroup/hdf5/issues/5549
github.com/user-attachments/files/20438441/hdf5_crash_1.txt