CVE-2016-4333
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
18/11/2016
Last modified:
12/04/2025
Description
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hdfgroup:hdf5:1.8.16:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.debian.org/security/2016/dsa-3727
- http://www.securityfocus.com/bid/94416
- http://www.talosintelligence.com/reports/TALOS-2016-0179/
- https://security.gentoo.org/glsa/201701-13
- http://www.debian.org/security/2016/dsa-3727
- http://www.securityfocus.com/bid/94416
- http://www.talosintelligence.com/reports/TALOS-2016-0179/
- https://security.gentoo.org/glsa/201701-13



