
Cloud Vulnerability DB
A community-led vulnerabilities database
HDF5 Library through version 1.14.3 contains a vulnerability where it may attempt to dereference uninitialized values in the h5tools_str_sprint function located in tools/lib/h5tools_str.c, which is called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c. The vulnerability was discovered and disclosed in May 2024, affecting all versions of HDF5 Library up to and including version 1.14.3 (HDF Group).
The vulnerability has been assigned a CVSS v3.1 Base Score of 5.7 (MEDIUM) with the following vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H. The issue is classified under CWE-908 (Use of Uninitialized Resource). The vulnerability specifically involves the potential dereferencing of uninitialized values in the h5tools_str_sprint function, which is called during data dumping operations (NVD).
The vulnerability can lead to potential security issues when processing HDF5 files, particularly during data dumping operations. The CVSS scoring indicates that while confidentiality impact is none, there is a low impact on integrity and a high impact on availability, suggesting that the primary risk is to system stability and reliability (NVD).
The vulnerability requires local access (AV:L) and has high attack complexity (AC:H), but requires no privileges (PR:N) or user interaction (UI:N). The scope is unchanged (S:U), indicating that the vulnerability can only affect resources managed by the same security authority (NVD).
The vulnerability has been fixed in HDF5 version 1.14.4, released on April 15, 2024. Users are advised to upgrade to this version to address this and several other security issues. The fix is part of a larger security update that addresses multiple CVEs discovered through fuzzing HDF5 files (HDF Group).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."