CVE-2020-10809

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
22/03/2020
Last modified:
30/04/2020

Description

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* 1.12.0 (including)