UBUNTU-CVE-2016-4333

Source
https://ubuntu.com/security/CVE-2016-4333
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-4333.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2016-4333
Related
Published
2016-11-18T20:59:00Z
Modified
2016-11-18T20:59:00Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.

References

Affected packages

Ubuntu:14.04:LTS / hdf5

Package

Name
hdf5
Purl
pkg:deb/ubuntu/hdf5?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.11-5ubuntu7.1

Affected versions

1.*

1.8.11-3ubuntu1
1.8.11-5ubuntu1
1.8.11-5ubuntu2
1.8.11-5ubuntu6
1.8.11-5ubuntu7

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "hdf5-helpers"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "hdf5-helpers-dbgsym"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "hdf5-tools"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "hdf5-tools-dbgsym"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-7"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-7-dbg"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-7-dbgsym"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-dev"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-doc"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-mpi-dev"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-mpich2-7"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-mpich2-7-dbg"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-mpich2-7-dbgsym"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-mpich2-dev"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-openmpi-7"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-openmpi-7-dbg"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-openmpi-7-dbgsym"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-openmpi-dev"
        },
        {
            "binary_version": "1.8.11-5ubuntu7.1",
            "binary_name": "libhdf5-serial-dev"
        }
    ]
}

Ubuntu:16.04:LTS / hdf5

Package

Name
hdf5
Purl
pkg:deb/ubuntu/hdf5?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.16+docs-4ubuntu1.1

Affected versions

1.*

1.8.15-patch1+docs-4
1.8.15-patch1+docs-5
1.8.16+docs-1
1.8.16+docs-2
1.8.16+docs-3
1.8.16+docs-3ubuntu1
1.8.16+docs-4
1.8.16+docs-4ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "hdf5-helpers"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "hdf5-tools"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "hdf5-tools-dbgsym"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-10"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-10-dbg"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-10-dbgsym"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-cpp-11"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-cpp-11-dbg"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-cpp-11-dbgsym"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-dev"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-doc"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-mpi-dev"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-mpich-10"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-mpich-10-dbg"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-mpich-10-dbgsym"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-mpich-dev"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-openmpi-10"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-openmpi-10-dbg"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-openmpi-10-dbgsym"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-openmpi-dev"
        },
        {
            "binary_version": "1.8.16+docs-4ubuntu1.1",
            "binary_name": "libhdf5-serial-dev"
        }
    ]
}