add CVE-2018-13871.
This commit is contained in:
parent
3d55f0d55d
commit
368fc95951
Binary file not shown.
|
@ -0,0 +1,3 @@
|
||||||
|
h5dump H5FL_blk_malloc-heap-buffer-overflow
|
||||||
|
|
||||||
|
段错误 (核心已转储)
|
|
@ -0,0 +1,19 @@
|
||||||
|
id: CVE-2018-13871
|
||||||
|
source: https://github.com/TeamSeri0us/pocs/tree/master/hdf5
|
||||||
|
info:
|
||||||
|
name: HDF5是一套免费的用于管理存储不同类型数据的工具套件,它能够管理、操作、查看、分析数据,并生成可移植格式的文件。
|
||||||
|
severity: high
|
||||||
|
description: |
|
||||||
|
HDF5 1.8.20版本中的H5FL.c文件的‘H5FL_blk_malloc’函数存在基于堆的缓冲区溢出漏洞。攻击者可通过诱使用户打开特制的文件利用该漏洞造成应用程序崩溃。
|
||||||
|
scope-of-influence:
|
||||||
|
hdf5:1.8.20
|
||||||
|
reference:
|
||||||
|
- https://nvd.nist.gov/vuln/detail/CVE-2018-13871
|
||||||
|
classification:
|
||||||
|
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
||||||
|
cvss-score: 9.8
|
||||||
|
cve-id: CVE-2018-13871
|
||||||
|
cwe-id: CWE-125
|
||||||
|
cnvd-id: None
|
||||||
|
kve-id: None
|
||||||
|
tags: CVE2018, hdf5
|
|
@ -92,6 +92,7 @@ cve:
|
||||||
hdf5:
|
hdf5:
|
||||||
- CVE-2018-13867
|
- CVE-2018-13867
|
||||||
- CVE-2018-13870
|
- CVE-2018-13870
|
||||||
|
- CVE-2018-13871
|
||||||
cnvd:
|
cnvd:
|
||||||
|
|
||||||
kve:
|
kve:
|
||||||
|
|
Loading…
Reference in New Issue