CVE-2016-4333

NameCVE-2016-4333
DescriptionThe HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-771-1, DSA-3727-1
NVD severitymedium (attack range: local)
Debian Bugs845301

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hdf5 (PTS)wheezy1.8.8-9vulnerable
wheezy (security)1.8.8-9+deb7u1fixed
jessie (security), jessie1.8.13+docs-15+deb8u1fixed
stretch1.10.0-patch1+docs-3fixed
buster, sid1.10.0-patch1+docs-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hdf5source(unstable)1.10.0-patch1+docs-1medium845301
hdf5sourcejessie1.8.13+docs-15+deb8u1mediumDSA-3727-1
hdf5sourcewheezy1.8.8-9+deb7u1mediumDLA-771-1

Notes

http://www.talosintelligence.com/reports/TALOS-2016-0179/
Fixed by: https://bitbucket.hdfgroup.org/projects/HDFFV/repos/hdf5/commits/73640612aad91d3f04e4d8f1ea71d42acbc85f6e

Search for package or bug name: Reporting problems