SUSE-SU-2022:1912-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1912-1
SUSE-SU-2022:1912-1
Summary: Security update for hdf5
Details: This update for hdf5 fixes the following issues: Security issues fixed: - CVE-2020-10811: Fixed heap-based buffer over-read in the function H5O__layout_decode() located in H5Olayout.c (bsc#1167405). - CVE-2020-10810: Fixed NULL pointer dereference in the function H5AC_unpin_entry() located in H5AC.c (bsc#1167401). - CVE-2020-10809: Fixed heap-based buffer overflow in the function Decompress() located in decompress.c (bsc#1167404). - CVE-2018-17438: Fixed SIGFPE signal raise in the function H5D__select_io() of H5Dselect.c (bsc#1109570). - CVE-2018-17437: Fixed memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c. (bsc#1109569). - CVE-2018-17436: Fixed issue in ReadCode() in decompress.c that allowed attackers to cause a denial of service via a crafted HDF5 file (bsc#1109568). - CVE-2018-17434: Fixed SIGFPE signal raise in function apply_filters() of h5repack_filters.c (bsc#1109566). - CVE-2018-17433: Fixed heap-based buffer overflow in ReadGifImageDesc() in gifread.c (bsc#1109565). - CVE-2018-17432: Fixed NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c (bsc#1109564). - CVE-2018-17237: Fixed SIGFPE signal raise in the function H5D__chunk_set_info_real() (bsc#1109168). - CVE-2018-17234: Fixed memory leak in the H5O__chunk_deserialize() function in H5Ocache.c (bsc#1109167). - CVE-2018-14460: Fixed heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c (bsc#1102175). - CVE-2018-14033: Fixed heap-based buffer over-read in the function H5O_layout_decode in H5Olayout.c (bsc#1101471). - CVE-2018-14032: Fixed heap-based buffer over-read in the function H5O_fill_new_decode in H5Ofill.c (bsc#1101474). - CVE-2018-11206: Fixed out of bounds read in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c (bsc#1093657). Bugfixes: - Fix python-h5py packages built against out-of-date version of HDF5 (bsc#1196682). - Fix netcdf-cxx4 packages built against out-of-date version of HDF5 (bsc#1179521).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221912-1/, https://bugzilla.suse.com/1093657, https://bugzilla.suse.com/1101471, https://bugzilla.suse.com/1101474, https://bugzilla.suse.com/1102175, https://bugzilla.suse.com/1109167, https://bugzilla.suse.com/1109168, https://bugzilla.suse.com/1109564, https://bugzilla.suse.com/1109565, https://bugzilla.suse.com/1109566, https://bugzilla.suse.com/1109568, https://bugzilla.suse.com/1109569, https://bugzilla.suse.com/1109570, https://bugzilla.suse.com/1167401, https://bugzilla.suse.com/1167404, https://bugzilla.suse.com/1167405, https://bugzilla.suse.com/1179521, https://bugzilla.suse.com/1196682, https://www.suse.com/security/cve/CVE-2018-11206, https://www.suse.com/security/cve/CVE-2018-14032, https://www.suse.com/security/cve/CVE-2018-14033, https://www.suse.com/security/cve/CVE-2018-14460, https://www.suse.com/security/cve/CVE-2018-17234, https://www.suse.com/security/cve/CVE-2018-17237, https://www.suse.com/security/cve/CVE-2018-17432, https://www.suse.com/security/cve/CVE-2018-17433, https://www.suse.com/security/cve/CVE-2018-17434, https://www.suse.com/security/cve/CVE-2018-17436, https://www.suse.com/security/cve/CVE-2018-17437, https://www.suse.com/security/cve/CVE-2018-17438, https://www.suse.com/security/cve/CVE-2020-10809, https://www.suse.com/security/cve/CVE-2020-10810, https://www.suse.com/security/cve/CVE-2020-10811
Affected packages
Package
Name: hdf5_1_10_8-gnu-hpc
Purl: pkg:rpm/suse/hdf5_1_10_8-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
