diff --git a/cve/hdf5/2018/CVE-2018-13867/H5F__accum_read-Out_Of_Bound_Read b/cve/hdf5/2018/CVE-2018-13867/H5F__accum_read-Out_Of_Bound_Read new file mode 100755 index 0000000000000000000000000000000000000000..f7570524aa12d120439d2b0e1a77d3715450b270 Binary files /dev/null and b/cve/hdf5/2018/CVE-2018-13867/H5F__accum_read-Out_Of_Bound_Read differ diff --git a/cve/hdf5/2018/CVE-2018-13867/README.md b/cve/hdf5/2018/CVE-2018-13867/README.md new file mode 100644 index 0000000000000000000000000000000000000000..173cdc97493a356017a4e8f293d4eeef9e5c0779 --- /dev/null +++ b/cve/hdf5/2018/CVE-2018-13867/README.md @@ -0,0 +1,3 @@ +h5dump H5F__accum_read-Out_Of_Bound_Read + +段错误 (核心已转储) \ No newline at end of file diff --git a/cve/hdf5/2018/yaml/CVE-2018-13867.yaml b/cve/hdf5/2018/yaml/CVE-2018-13867.yaml new file mode 100644 index 0000000000000000000000000000000000000000..ea45b40c498167336152fb38bdbdc0e59ca165c1 --- /dev/null +++ b/cve/hdf5/2018/yaml/CVE-2018-13867.yaml @@ -0,0 +1,19 @@ +id: CVE-2018-13867 +source: https://github.com/TeamSeri0us/pocs/tree/master/hdf5 +info: + name: HDF5是一套免费的用于管理存储不同类型数据的工具套件,它能够管理、操作、查看、分析数据,并生成可移植格式的文件。 + severity: high + description: | + HDF5 1.8.20版本中的H5Faccum.c文件的‘H5F__accum_read’函数存在越界读取漏洞。攻击者可通过诱使用户打开特制的文件利用该漏洞造成应用程序崩溃。 + scope-of-influence: + hdf5:1.8.20 + reference: + - https://nvd.nist.gov/vuln/detail/CVE-2018-13867 + classification: + cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H + cvss-score: 9.8 + cve-id: CVE-2018-13867 + cwe-id: CWE-125 + cnvd-id: None + kve-id: None + tags: CVE2018, hdf5 \ No newline at end of file diff --git a/openkylin_list.yaml b/openkylin_list.yaml index 65c56aef7fad3a5437d6d9304d18b6548f26fcc6..6faa9354bbac4c75699a80bccc6cefe7c9e55c4c 100644 --- a/openkylin_list.yaml +++ b/openkylin_list.yaml @@ -89,6 +89,8 @@ cve: - CVE-2023-1175 - CVE-2023-1264 - CVE-2023-1355 + hdf5: + - CVE-2018-13867 cnvd: kve: