HDF5 2.2.0 版本之前,位于 src/H5VM.c 中的 H5VM_array_fill() 函数存在基于堆的缓冲区溢出漏洞。攻击者可以通过构造特定的 HDF5 文件,导致远程应用程序崩溃,并可能执行任意代码。当读取数据集中未分配的数据块时,H5D__fill_init() 会利用文件中的数据类型和数据空间元数据来填充填充值缓冲区。如果这些元数据与缓冲区实际分配大小不一致,写入操作就会超出缓冲区边界。攻击者可以通过文件中存储的填充值控制写入的内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The HDF Group | HDF5 | 1.10.0 ~ 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet