CVE-2016-4333
8.6
HIGH
CVSS 3.1
EPSS 0.61%
描述
The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.
如何修補 CVE-2016-4333
要修補 CVE-2016-4333,請將受影響套件升級到下列已修補版本。
- Debian/hdf5—升級至 1.10.0-patch1+docs-1 或更新版本
CVE-2016-4333 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.10.0-patch1+docs-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.6 | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |