HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 03:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux Ai |
|
CPEs | cpe:/a:redhat:enterprise_linux_ai:1.5::el9 | |
Vendors & Products |
Redhat
Redhat enterprise Linux Ai |
Thu, 13 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hdfgroup
Hdfgroup hdf5 |
|
CPEs | cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hdfgroup
Hdfgroup hdf5 |
|
Metrics |
ssvc
|
Tue, 20 Aug 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-122 | |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-05-09T16:43:49.875Z
Updated: 2025-02-13T15:52:25.069Z
Reserved: 2024-04-16T00:00:00.000Z
Link: CVE-2024-32617

Updated: 2024-08-02T02:13:40.225Z

Status : Analyzed
Published: 2024-05-14T15:36:46.893
Modified: 2025-04-18T14:33:50.773
Link: CVE-2024-32617
