5.3
CVSSv3

CVE-2025-2310

CVSSv4: 4.8 | CVSSv3: 5.3 | CVSSv2: 4.3 | VMScore: 580 | EPSS: 0.00019 | KEV: Not Included
Published: 14/03/2025 Updated: 08/05/2025

Vulnerability Summary

Heap-Based Buffer Overflow in HDF5 1.14.6 Metadata Attribute Decoder

A critical vulnerability exists in HDF5 version 1.14.6, specifically impacting the H5MM_strndup function within the Metadata Attribute Decoder component. The vulnerability can result in a heap-based buffer overflow when locally manipulated. While the exploit has been publicly disclosed, the actual existence of the vulnerability remains uncertain. The vendor was initially contacted about multiple vulnerabilities and responded with a blanket "reject" without providing additional context. Despite polite requests for further explanation, no elaboration was received. At present, it appears the vendor is attempting to dispute the vulnerability findings, and the issue remains flagged pending more detailed information.

Vulnerable Product Search on Vulmon Subscribe to Product

* hdf5

Vendor Advisories

Debian Bug report logs - #1103540 hdf5: CVE-2025-2310 Package: src:hdf5; Maintainer for src:hdf5 is Gilles Filippini <pini@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 18 Apr 2025 19:45:02 UTC Severity: important Tags: security, upstream Found in version hdf5/1145+repack-3 Rep ...