Medium severity6.5NVD Advisory· Published Sep 24, 2018· Updated Jun 17, 2026
CVE-2018-17435
CVE-2018-17435
Description
A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting an HDF file to GIF file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
33- osv-coords32 versionspkg:rpm/suse/hdf5_1_10_8-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/hdf5_1_10_8-gnu-mpich-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-mpich-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-mpich-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-mpich-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-mpich-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-mpich-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-mvapich2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-mvapich2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-mvapich2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-mvapich2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-mvapich2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-mvapich2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-mvapich2-hpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/hdf5_1_10_8-gnu-openmpi1-hpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/hdf5_1_10_8-gnu-openmpi2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-openmpi2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-openmpi2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-openmpi2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-openmpi2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-openmpi2-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/hdf5_1_10_8-gnu-openmpi3-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/hdf5_1_10_8-gnu-openmpi3-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/suse-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/suse-hpc&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/suse-hpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012
< 1.10.8-150100.7.4.3+ 31 more
- (no CPE)range: < 1.10.8-150100.7.4.3
- (no CPE)range: < 1.10.8-150100.7.4.3
- (no CPE)range: < 1.10.8-150200.8.4.2
- (no CPE)range: < 1.10.8-150200.8.4.2
- (no CPE)range: < 1.10.8-150000.8.4.3
- (no CPE)range: < 1.10.8-150000.8.4.3
- (no CPE)range: < 1.10.8-3.12.2
- (no CPE)range: < 1.10.8-150100.7.4.3
- (no CPE)range: < 1.10.8-150100.7.4.3
- (no CPE)range: < 1.10.8-150200.8.4.3
- (no CPE)range: < 1.10.8-150200.8.4.3
- (no CPE)range: < 1.10.8-150000.8.4.3
- (no CPE)range: < 1.10.8-150000.8.4.3
- (no CPE)range: < 1.10.8-150100.7.4.3
- (no CPE)range: < 1.10.8-150100.7.4.3
- (no CPE)range: < 1.10.8-150200.8.4.2
- (no CPE)range: < 1.10.8-150200.8.4.2
- (no CPE)range: < 1.10.8-150000.8.4.3
- (no CPE)range: < 1.10.8-150000.8.4.3
- (no CPE)range: < 1.10.8-3.12.2
- (no CPE)range: < 1.10.8-3.12.2
- (no CPE)range: < 1.10.8-150100.7.4.3
- (no CPE)range: < 1.10.8-150100.7.4.3
- (no CPE)range: < 1.10.8-150200.8.4.2
- (no CPE)range: < 1.10.8-150200.8.4.2
- (no CPE)range: < 1.10.8-150000.8.4.3
- (no CPE)range: < 1.10.8-150000.8.4.3
- (no CPE)range: < 1.10.8-150200.8.4.2
- (no CPE)range: < 1.10.8-150200.8.4.2
- (no CPE)range: < 0.5.20220206.0c6b168-150000.11.3.1
- (no CPE)range: < 0.5.20220206.0c6b168-150000.11.3.1
- (no CPE)range: < 0.5.20220206.0c6b168-5.2
Patches
Vulnerability mechanics
References
1- github.com/SegfaultMasters/covering360/tree/master/HDF5/vuln7nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.