CVE-2016-4332
Summary
| CVE | CVE-2016-4332 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-11-18 20:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library. |
Risk And Classification
Primary CVSS: v3.0 8.6 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS: 0.001100000 probability, percentile 0.288560000 (date 2026-05-10)
Problem Types: CWE-20 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 8.6 | HIGH | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.9 | AV:L/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3727-1 hdf5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Cisco Talos - Talos 2016 0178 | af854a3a-2127-422b-91ae-364da2661108 | www.talosintelligence.com | Exploit, Technical Description, Third Party Advisory |
| HDF5: Multiple vulnerabilities (GLSA 201701-13) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| HDF5 CVE-2016-4332 Local Heap Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.