Bug 1202621 - (CVE-2022-25972) VUL-0: CVE-2022-25972: hdf5: out-of-bounds write vulnerability in the gif2h5 functionality
(CVE-2022-25972)
VUL-0: CVE-2022-25972: hdf5: out-of-bounds write vulnerability in the gif2h5 ...
Status: RESOLVED UPSTREAM
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: HPC Issue Tracker
Security Team bot
https://smash.suse.de/issue/340422/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-08-23 06:43 UTC by Alexander Bergmann
Modified: 2022-09-07 07:19 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2022-08-23 06:43:26 UTC
CVE-2022-25972

An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5
Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution.
An attacker can provide a malicious file to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-25972
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25972
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1485
Comment 1 Alexander Bergmann 2022-08-23 07:10:13 UTC
From the version numbers all SUSE related packages seam to be clear.

SUSE:SLE-12-SP2:GA:Products:Update/hdf5  hdf5-1.10.8
SUSE:SLE-15:Update/hdf5                  hdf5-1.10.8
SUSE:SLE-15-SP1:Update/hdf5              hdf5-1.10.8
SUSE:SLE-15-SP2:Update/hdf5              hdf5-1.10.8
SUSE:SLE-15-SP3:Update/hdf5              hdf5-1.10.8
SUSE:SLE-15-SP4:GA/hdf5                  hdf5-1.10.8


There is no direct reference to a patch or git commit. We will leave the bug report open to check the correctness.
Comment 4 Gabriele Sonnu 2022-09-07 07:19:39 UTC
Not affected since we don't ship the GIF tools. Closing.