{"id":"OSV-2023-1091","summary":"Heap-buffer-overflow in H5F_addr_decode","details":"OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=63743\n\n```\nCrash type: Heap-buffer-overflow READ 1\nCrash state:\nH5F_addr_decode\nH5O__shared_decode\nH5O__fill_new_shared_decode\n```\n","modified":"2025-03-18T00:45:36.194874Z","published":"2023-10-31T13:01:22.289748Z","references":[{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=63743"}],"affected":[{"package":{"name":"hdf5","ecosystem":"OSS-Fuzz","purl":"pkg:generic/hdf5"},"ranges":[{"type":"GIT","repo":"https://github.com/HDFGroup/hdf5","events":[{"introduced":"966454aac1231da7209ef81c11055d3312181f99"},{"introduced":"04f0647727677d716a3c1c772d35a660a8ea0dc5"},{"introduced":"5a0ec52099cf02224a4066b158bcf1a34829db20"},{"introduced":"f527239564fc27a6e666ce734b88e4ab18765efc"},{"fixed":"589f5238feae51787d3925fba0cb39b1cbabf8d5"}]}],"versions":["1.14.1","hdf5-1_10_10","hdf5-1_10_11","hdf5-1_12_3","hdf5-1_14_1","hdf5-1_14_1-2","hdf5-1_14_2","hdf5-1_14_3","hdf5-1_14_3-rc1","hdf5_1.14.4","hdf5_1.14.4.1","hdf5_1.14.4.2","snapshot-1.10","snapshot-1.12","snapshot-1.14","hdf5_1.14.4.3","hdf5_1.14.5","hdf5-1.14.5","hdf5-1.14.6","hdf5_1.14.6","hdff5-1_14-_0","hdff5-1_14_0"],"ecosystem_specific":{"severity":"MEDIUM"},"database_specific":{"source":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/hdf5/OSV-2023-1091.yaml","fixed_range":"203a95abb5e2420e3ae7d258f03a87464d48618e:589f5238feae51787d3925fba0cb39b1cbabf8d5"}}],"schema_version":"1.7.3"}