CVE-2016-4333

NameCVE-2016-4333
DescriptionThe HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-771-1, DSA-3727-1
Debian Bugs845301

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hdf5 (PTS)jessie, jessie (lts)1.8.13+docs-15+deb8u1fixed
stretch (lts), stretch1.10.0-patch1+docs-3+deb9u2fixed
buster (security), buster, buster (lts)1.10.4+repack-10+deb10u1fixed
bullseye1.10.6+repack-4+deb11u1fixed
bookworm1.10.8+repack1-1fixed
trixie1.10.10+repack-5fixed
sid1.14.5+repack-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hdf5sourcewheezy1.8.8-9+deb7u1DLA-771-1
hdf5sourcejessie1.8.13+docs-15+deb8u1DSA-3727-1
hdf5source(unstable)1.10.0-patch1+docs-1845301

Notes

http://www.talosintelligence.com/reports/TALOS-2016-0179/
Fixed by: https://bitbucket.hdfgroup.org/projects/HDFFV/repos/hdf5/commits/73640612aad91d3f04e4d8f1ea71d42acbc85f6e

Search for package or bug name: Reporting problems