When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.talosintelligence.com/reports/TALOS-2016-0177/ | exploit third party advisory technical description |
http://www.securityfocus.com/bid/94411 | vdb entry |
https://security.gentoo.org/glsa/201701-13 | vendor advisory |
http://www.debian.org/security/2016/dsa-3727 | vendor advisory |