A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5FS__sect_find_node of the file H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://github.com/HDFGroup/hdf5/issues/5580 | Exploit Issue Tracking |
https://github.com/HDFGroup/hdf5/issues/5580 | Exploit Issue Tracking |
https://github.com/user-attachments/files/20626642/reproduce.tar.gz | Exploit |
https://vuldb.com/?ctiid.313274 | Permissions Required Third Party Advisory VDB Entry |
https://vuldb.com/?id.313274 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.592588 | Third Party Advisory VDB Entry |
Configurations
History
02 Jul 2025, 19:02
Type | Values Removed | Values Added |
---|---|---|
First Time |
Hdfgroup hdf5
Hdfgroup |
|
CPE | cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* | |
References | () https://github.com/user-attachments/files/20626642/reproduce.tar.gz - Exploit | |
References | () https://github.com/HDFGroup/hdf5/issues/5580 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?ctiid.313274 - Permissions Required, Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?id.313274 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.592588 - Third Party Advisory, VDB Entry |
23 Jun 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-119 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
19 Jun 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-19 17:15
Updated : 2025-07-02 19:02
NVD link : CVE-2025-6270
Mitre link : CVE-2025-6270
JSON object : View
Products Affected
hdfgroup
- hdf5
CWE
No CWE.