CVE Vulnerabilities

CVE-2021-45832

Uncontrolled Recursion

Published: Jan 05, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service (context-dependent).

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

Name Vendor Start Version End Version
Hdf5 Hdfgroup 1.13.1-1 (including) 1.13.1-1 (including)
Hdf5 Ubuntu bionic *
Hdf5 Ubuntu hirsute *
Hdf5 Ubuntu impish *
Hdf5 Ubuntu kinetic *
Hdf5 Ubuntu lunar *
Hdf5 Ubuntu mantic *
Hdf5 Ubuntu trusty *
Hdf5 Ubuntu trusty/esm *
Hdf5 Ubuntu xenial *
Insighttoolkit5 Ubuntu kinetic *
Insighttoolkit5 Ubuntu lunar *
Insighttoolkit5 Ubuntu mantic *
Insighttoolkit5 Ubuntu trusty *
Insighttoolkit5 Ubuntu xenial *
Paraview Ubuntu bionic *
Paraview Ubuntu hirsute *
Paraview Ubuntu impish *
Paraview Ubuntu kinetic *
Paraview Ubuntu lunar *
Paraview Ubuntu mantic *
Paraview Ubuntu trusty *
Paraview Ubuntu xenial *

Potential Mitigations

References