Bugzilla – Bug 1202620
VUL-0: CVE-2022-25942: hdf5: out-of-bounds read vulnerability in the gif2h5 functionality
Last modified: 2022-09-07 07:19:19 UTC
CVE-2022-25942 An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-25942 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25942 https://talosintelligence.com/vulnerability_reports/TALOS-2022-1486
From the version numbers all SUSE related packages seam to be clear. SUSE:SLE-12-SP2:GA:Products:Update/hdf5 hdf5-1.10.8 SUSE:SLE-15:Update/hdf5 hdf5-1.10.8 SUSE:SLE-15-SP1:Update/hdf5 hdf5-1.10.8 SUSE:SLE-15-SP2:Update/hdf5 hdf5-1.10.8 SUSE:SLE-15-SP3:Update/hdf5 hdf5-1.10.8 SUSE:SLE-15-SP4:GA/hdf5 hdf5-1.10.8 There is no direct reference to a patch or git commit. We will leave the bug report open to check the correctness.
Not affected since we don't ship the GIF tools. Closing.