#VU63941 Resource exhaustion in HDF5 - CVE-2018-17437
Published: June 2, 2022 / Updated: March 9, 2023
HDF5
HDF Group
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5. A remote attacker can trick the victim into opening a specially crafted HDF5 file and perform a denial of service attack.