HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/ | vendor advisory issue tracking |
https://github.com/HDFGroup/cve_hdf5/blob/main/CVE_list.md | third party advisory |