OSV-2023-471

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/hdf5/OSV-2023-471.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-471
Published
2023-06-09T14:00:54.620201Z
Modified
2024-04-29T14:35:35.936516Z
Summary
Heap-buffer-overflow in H5FS__sinfo_serialize_node_cb
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=59695

Crash type: Heap-buffer-overflow WRITE 1
Crash state:
H5FS__sinfo_serialize_node_cb
H5SL_iterate
H5FS__cache_sinfo_serialize
References

Affected packages

OSS-Fuzz / hdf5

Package

Name
hdf5
Purl
pkg:generic/hdf5

Affected versions

1.*

1.14.1

Other

hdf5-1_10_10
hdf5-1_10_11
hdf5-1_12_3
hdf5-1_14_1
hdf5-1_14_1-2
hdf5-1_14_2
hdf5-1_14_3
hdf5-1_14_3-rc1

hdf5_1.*

hdf5_1.14.4
hdf5_1.14.4.1
hdf5_1.14.4.2

snapshot-1.*

snapshot-1.10
snapshot-1.12
snapshot-1.14

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

{
    "fixed_range": "203a95abb5e2420e3ae7d258f03a87464d48618e:589f5238feae51787d3925fba0cb39b1cbabf8d5"
}