CVE Vulnerabilities

CVE-2021-46243

NULL Pointer Dereference

Published: Jan 21, 2022 | Modified: Jan 28, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.2 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Hdf5 Hdfgroup 1.13.1-1 (including) 1.13.1-1 (including)
Hdf5 Ubuntu bionic *
Hdf5 Ubuntu impish *
Hdf5 Ubuntu kinetic *
Hdf5 Ubuntu lunar *
Hdf5 Ubuntu mantic *
Hdf5 Ubuntu trusty *
Hdf5 Ubuntu xenial *
Insighttoolkit4 Ubuntu bionic *
Insighttoolkit4 Ubuntu impish *
Insighttoolkit4 Ubuntu kinetic *
Insighttoolkit4 Ubuntu lunar *
Insighttoolkit4 Ubuntu trusty *
Insighttoolkit4 Ubuntu xenial *
Kissplice Ubuntu bionic *
Kissplice Ubuntu impish *
Kissplice Ubuntu kinetic *
Kissplice Ubuntu lunar *
Kissplice Ubuntu mantic *
Kissplice Ubuntu trusty *
Kissplice Ubuntu xenial *
Paraview Ubuntu bionic *
Paraview Ubuntu impish *
Paraview Ubuntu kinetic *
Paraview Ubuntu lunar *
Paraview Ubuntu mantic *
Paraview Ubuntu trusty *
Paraview Ubuntu xenial *
Vtk Ubuntu trusty *
Vtk Ubuntu xenial *
Xdmf Ubuntu bionic *
Xdmf Ubuntu impish *
Xdmf Ubuntu kinetic *
Xdmf Ubuntu lunar *
Xdmf Ubuntu mantic *
Xdmf Ubuntu trusty *
Xdmf Ubuntu xenial *

Potential Mitigations

References