diff --git a/cve/hdf5/2018/CVE-2018-13871/H5FL_blk_malloc-heap-buffer-overflow b/cve/hdf5/2018/CVE-2018-13871/H5FL_blk_malloc-heap-buffer-overflow new file mode 100755 index 00000000..6516bd86 Binary files /dev/null and b/cve/hdf5/2018/CVE-2018-13871/H5FL_blk_malloc-heap-buffer-overflow differ diff --git a/cve/hdf5/2018/CVE-2018-13871/README.md b/cve/hdf5/2018/CVE-2018-13871/README.md new file mode 100644 index 00000000..0691e98e --- /dev/null +++ b/cve/hdf5/2018/CVE-2018-13871/README.md @@ -0,0 +1,3 @@ +h5dump H5FL_blk_malloc-heap-buffer-overflow + +段错误 (核心已转储) diff --git a/cve/hdf5/2018/yaml/CVE-2018-13871.yaml b/cve/hdf5/2018/yaml/CVE-2018-13871.yaml new file mode 100644 index 00000000..5b1448ac --- /dev/null +++ b/cve/hdf5/2018/yaml/CVE-2018-13871.yaml @@ -0,0 +1,19 @@ +id: CVE-2018-13871 +source: https://github.com/TeamSeri0us/pocs/tree/master/hdf5 +info: + name: HDF5是一套免费的用于管理存储不同类型数据的工具套件,它能够管理、操作、查看、分析数据,并生成可移植格式的文件。 + severity: high + description: | + HDF5 1.8.20版本中的H5FL.c文件的‘H5FL_blk_malloc’函数存在基于堆的缓冲区溢出漏洞。攻击者可通过诱使用户打开特制的文件利用该漏洞造成应用程序崩溃。 + scope-of-influence: + hdf5:1.8.20 + reference: + - https://nvd.nist.gov/vuln/detail/CVE-2018-13871 + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H + cvss-score: 9.8 + cve-id: CVE-2018-13871 + cwe-id: CWE-125 + cnvd-id: None + kve-id: None + tags: CVE2018, hdf5 \ No newline at end of file diff --git a/openkylin_list.yaml b/openkylin_list.yaml index 9f241768..2fe5716b 100644 --- a/openkylin_list.yaml +++ b/openkylin_list.yaml @@ -92,6 +92,7 @@ cve: hdf5: - CVE-2018-13867 - CVE-2018-13870 + - CVE-2018-13871 cnvd: kve: