rpm package
suse/pmix&distro=SUSE Linux Enterprise Module for HPC 15 SP5
pkg:rpm/suse/pmix&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP5
Vulnerabilities (14)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-32608 | Cri | 9.8 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | Oct 9, 2024 | HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. | |
| CVE-2024-33875 | Med | 5.7 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer. | |
| CVE-2024-33874 | Cri | 9.8 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c. | |
| CVE-2024-33873 | Hig | 8.8 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c. | |
| CVE-2024-32620 | Hig | 7.4 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer. | |
| CVE-2024-32619 | Hig | 7.4 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer. | |
| CVE-2024-32614 | Hig | 8.8 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c. | |
| CVE-2024-32610 | Med | 5.7 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer. | |
| CVE-2024-29166 | Med | 5.7 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. | |
| CVE-2024-29161 | Hig | 8.8 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. | |
| CVE-2024-29158 | Hig | 7.4 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 14, 2024 | HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. | |
| CVE-2023-41915 | Hig | 8.1 | < 3.2.3-150300.3.8.1 | 3.2.3-150300.3.8.1 | Sep 9, 2023 | OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0. | |
| CVE-2018-11205 | Hig | 8.1 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | May 16, 2018 | A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack. | |
| CVE-2017-17507 | Med | 6.5 | < 3.2.3-150300.3.10.1 | 3.2.3-150300.3.10.1 | Dec 11, 2017 | In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file. |
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
- affected < 3.2.3-150300.3.8.1fixed 3.2.3-150300.3.8.1
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.
- affected < 3.2.3-150300.3.10.1fixed 3.2.3-150300.3.10.1
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.