From 368fc959515713eb924fd5555dca24f83959e832 Mon Sep 17 00:00:00 2001 From: "LI, WENJIE" Date: Thu, 9 Nov 2023 09:56:02 +0800 Subject: [PATCH] add CVE-2018-13871. --- .../H5FL_blk_malloc-heap-buffer-overflow | Bin 0 -> 1952 bytes cve/hdf5/2018/CVE-2018-13871/README.md | 3 +++ cve/hdf5/2018/yaml/CVE-2018-13871.yaml | 19 ++++++++++++++++++ openkylin_list.yaml | 1 + 4 files changed, 23 insertions(+) create mode 100755 cve/hdf5/2018/CVE-2018-13871/H5FL_blk_malloc-heap-buffer-overflow create mode 100644 cve/hdf5/2018/CVE-2018-13871/README.md create mode 100644 cve/hdf5/2018/yaml/CVE-2018-13871.yaml diff --git a/cve/hdf5/2018/CVE-2018-13871/H5FL_blk_malloc-heap-buffer-overflow b/cve/hdf5/2018/CVE-2018-13871/H5FL_blk_malloc-heap-buffer-overflow new file mode 100755 index 0000000000000000000000000000000000000000..6516bd862481e42b5d889f3973cd528761fcbf6c GIT binary patch literal 1952 zcmeD5aB<`1lHy_j0S*oZ76t(ZW-tdr{D*=C?5KR0k_Ax3j8K6FC?f&N_i%L#05hTD z0x)$@8b;;kq#!F}_yCg_=5$Dqt1ANoBLgg)VKmI!5o{0^2TWj;9#J8{$iM_l9SjT# zP+toI^CyVk0L@PcP;nRq&2O+|1f#h=AZKczVyJeYX%GNOhYX|X5EhW5G)f5IN{1XQ i5M>w8(pRvbzY8NUmBGp_4QM$AOLw^Rp;$V~VE_R15K(#n literal 0 HcmV?d00001 diff --git a/cve/hdf5/2018/CVE-2018-13871/README.md b/cve/hdf5/2018/CVE-2018-13871/README.md new file mode 100644 index 00000000..0691e98e --- /dev/null +++ b/cve/hdf5/2018/CVE-2018-13871/README.md @@ -0,0 +1,3 @@ +h5dump H5FL_blk_malloc-heap-buffer-overflow + +段错误 (核心已转储) diff --git a/cve/hdf5/2018/yaml/CVE-2018-13871.yaml b/cve/hdf5/2018/yaml/CVE-2018-13871.yaml new file mode 100644 index 00000000..5b1448ac --- /dev/null +++ b/cve/hdf5/2018/yaml/CVE-2018-13871.yaml @@ -0,0 +1,19 @@ +id: CVE-2018-13871 +source: https://github.com/TeamSeri0us/pocs/tree/master/hdf5 +info: + name: HDF5是一套免费的用于管理存储不同类型数据的工具套件,它能够管理、操作、查看、分析数据,并生成可移植格式的文件。 + severity: high + description: | + HDF5 1.8.20版本中的H5FL.c文件的‘H5FL_blk_malloc’函数存在基于堆的缓冲区溢出漏洞。攻击者可通过诱使用户打开特制的文件利用该漏洞造成应用程序崩溃。 + scope-of-influence: + hdf5:1.8.20 + reference: + - https://nvd.nist.gov/vuln/detail/CVE-2018-13871 + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H + cvss-score: 9.8 + cve-id: CVE-2018-13871 + cwe-id: CWE-125 + cnvd-id: None + kve-id: None + tags: CVE2018, hdf5 \ No newline at end of file diff --git a/openkylin_list.yaml b/openkylin_list.yaml index 9f241768..2fe5716b 100644 --- a/openkylin_list.yaml +++ b/openkylin_list.yaml @@ -92,6 +92,7 @@ cve: hdf5: - CVE-2018-13867 - CVE-2018-13870 + - CVE-2018-13871 cnvd: kve: