<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for hdf5</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2018:1056-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2018-04-23T21:43:02Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2018-04-23T21:43:02Z</InitialReleaseDate>
    <CurrentReleaseDate>2018-04-23T21:43:02Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for hdf5</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for hdf5 fixes the following issues:

- fix security issues (arbitary code execution):
  CVE-2016-4330: H5T_ARRAY Code Execution (boo#1011201)
  CVE-2016-4331: H5Z_NBIT Code Execution (boo#1011204)
  CVE-2016-4332: Shareable Message Type Code Execution (boo#1011205)
  CVE-2016-4333: Array index bounds issue (boo#1011198)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2018-392</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI/#Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI</URL>
      <Description>E-Mail link for openSUSE-SU-2018:1056-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1011198</URL>
      <Description>SUSE Bug 1011198</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1011201</URL>
      <Description>SUSE Bug 1011201</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1011204</URL>
      <Description>SUSE Bug 1011204</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1011205</URL>
      <Description>SUSE Bug 1011205</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-4330/</URL>
      <Description>SUSE CVE CVE-2016-4330 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-4331/</URL>
      <Description>SUSE CVE CVE-2016-4331 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-4332/</URL>
      <Description>SUSE CVE CVE-2016-4332 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-4333/</URL>
      <Description>SUSE CVE CVE-2016-4333 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub 12">
      <Branch Type="Product Name" Name="SUSE Package Hub 12">
        <FullProductName ProductID="SUSE Package Hub 12" CPE="cpe:/o:suse:packagehub:12">SUSE Package Hub 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="hdf5-1.8.17-5.1">
      <FullProductName ProductID="hdf5-1.8.17-5.1">hdf5-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="hdf5-devel-1.8.17-5.1">
      <FullProductName ProductID="hdf5-devel-1.8.17-5.1">hdf5-devel-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="hdf5-devel-data-1.8.17-5.1">
      <FullProductName ProductID="hdf5-devel-data-1.8.17-5.1">hdf5-devel-data-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="hdf5-devel-static-1.8.17-5.1">
      <FullProductName ProductID="hdf5-devel-static-1.8.17-5.1">hdf5-devel-static-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="hdf5-examples-1.8.17-5.1">
      <FullProductName ProductID="hdf5-examples-1.8.17-5.1">hdf5-examples-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="hdf5-openmpi-1.8.17-5.1">
      <FullProductName ProductID="hdf5-openmpi-1.8.17-5.1">hdf5-openmpi-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="hdf5-openmpi-devel-1.8.17-5.1">
      <FullProductName ProductID="hdf5-openmpi-devel-1.8.17-5.1">hdf5-openmpi-devel-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="hdf5-openmpi-devel-static-1.8.17-5.1">
      <FullProductName ProductID="hdf5-openmpi-devel-static-1.8.17-5.1">hdf5-openmpi-devel-static-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5-10-1.8.17-5.1">
      <FullProductName ProductID="libhdf5-10-1.8.17-5.1">libhdf5-10-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5-10-openmpi-1.8.17-5.1">
      <FullProductName ProductID="libhdf5-10-openmpi-1.8.17-5.1">libhdf5-10-openmpi-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5_cpp12-1.8.17-5.1">
      <FullProductName ProductID="libhdf5_cpp12-1.8.17-5.1">libhdf5_cpp12-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5_fortran10-1.8.17-5.1">
      <FullProductName ProductID="libhdf5_fortran10-1.8.17-5.1">libhdf5_fortran10-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5_fortran10-openmpi-1.8.17-5.1">
      <FullProductName ProductID="libhdf5_fortran10-openmpi-1.8.17-5.1">libhdf5_fortran10-openmpi-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5_hl10-1.8.17-5.1">
      <FullProductName ProductID="libhdf5_hl10-1.8.17-5.1">libhdf5_hl10-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5_hl10-openmpi-1.8.17-5.1">
      <FullProductName ProductID="libhdf5_hl10-openmpi-1.8.17-5.1">libhdf5_hl10-openmpi-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5_hl_cpp11-1.8.17-5.1">
      <FullProductName ProductID="libhdf5_hl_cpp11-1.8.17-5.1">libhdf5_hl_cpp11-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5hl_fortran10-1.8.17-5.1">
      <FullProductName ProductID="libhdf5hl_fortran10-1.8.17-5.1">libhdf5hl_fortran10-1.8.17-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libhdf5hl_fortran10-openmpi-1.8.17-5.1">
      <FullProductName ProductID="libhdf5hl_fortran10-openmpi-1.8.17-5.1">libhdf5hl_fortran10-openmpi-1.8.17-5.1</FullProductName>
    </Branch>
    <Relationship ProductReference="hdf5-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:hdf5-1.8.17-5.1">hdf5-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="hdf5-devel-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:hdf5-devel-1.8.17-5.1">hdf5-devel-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="hdf5-devel-data-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:hdf5-devel-data-1.8.17-5.1">hdf5-devel-data-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="hdf5-devel-static-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:hdf5-devel-static-1.8.17-5.1">hdf5-devel-static-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="hdf5-examples-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:hdf5-examples-1.8.17-5.1">hdf5-examples-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="hdf5-openmpi-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:hdf5-openmpi-1.8.17-5.1">hdf5-openmpi-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="hdf5-openmpi-devel-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:hdf5-openmpi-devel-1.8.17-5.1">hdf5-openmpi-devel-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="hdf5-openmpi-devel-static-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:hdf5-openmpi-devel-static-1.8.17-5.1">hdf5-openmpi-devel-static-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5-10-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5-10-1.8.17-5.1">libhdf5-10-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5-10-openmpi-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5-10-openmpi-1.8.17-5.1">libhdf5-10-openmpi-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5_cpp12-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5_cpp12-1.8.17-5.1">libhdf5_cpp12-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5_fortran10-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5_fortran10-1.8.17-5.1">libhdf5_fortran10-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5_fortran10-openmpi-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5_fortran10-openmpi-1.8.17-5.1">libhdf5_fortran10-openmpi-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5_hl10-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5_hl10-1.8.17-5.1">libhdf5_hl10-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5_hl10-openmpi-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5_hl10-openmpi-1.8.17-5.1">libhdf5_hl10-openmpi-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5_hl_cpp11-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5_hl_cpp11-1.8.17-5.1">libhdf5_hl_cpp11-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5hl_fortran10-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5hl_fortran10-1.8.17-5.1">libhdf5hl_fortran10-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libhdf5hl_fortran10-openmpi-1.8.17-5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:libhdf5hl_fortran10-openmpi-1.8.17-5.1">libhdf5hl_fortran10-openmpi-1.8.17-5.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.</Note>
    </Notes>
    <CVE>CVE-2016-4330</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:hdf5-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-data-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-static-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-examples-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-devel-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-devel-static-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5-10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5-10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_cpp12-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_fortran10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_fortran10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl_cpp11-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5hl_fortran10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5hl_fortran10-openmpi-1.8.17-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI/#Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4330.html</URL>
        <Description>CVE-2016-4330</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1011201</URL>
        <Description>SUSE Bug 1011201</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.</Note>
    </Notes>
    <CVE>CVE-2016-4331</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:hdf5-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-data-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-static-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-examples-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-devel-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-devel-static-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5-10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5-10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_cpp12-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_fortran10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_fortran10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl_cpp11-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5hl_fortran10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5hl_fortran10-openmpi-1.8.17-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI/#Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4331.html</URL>
        <Description>CVE-2016-4331</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1011204</URL>
        <Description>SUSE Bug 1011204</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.</Note>
    </Notes>
    <CVE>CVE-2016-4332</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:hdf5-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-data-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-static-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-examples-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-devel-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-devel-static-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5-10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5-10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_cpp12-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_fortran10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_fortran10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl_cpp11-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5hl_fortran10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5hl_fortran10-openmpi-1.8.17-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI/#Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4332.html</URL>
        <Description>CVE-2016-4332</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1011205</URL>
        <Description>SUSE Bug 1011205</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.</Note>
    </Notes>
    <CVE>CVE-2016-4333</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:hdf5-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-data-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-devel-static-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-examples-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-devel-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:hdf5-openmpi-devel-static-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5-10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5-10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_cpp12-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_fortran10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_fortran10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl10-openmpi-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5_hl_cpp11-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5hl_fortran10-1.8.17-5.1</ProductID>
        <ProductID>SUSE Package Hub 12:libhdf5hl_fortran10-openmpi-1.8.17-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.1</BaseScore>
        <Vector>AV:L/AC:M/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI/#Q6WDDNJ3NEYHLHLN6YSKTURIF42SBRMI</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-4333.html</URL>
        <Description>CVE-2016-4333</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1011198</URL>
        <Description>SUSE Bug 1011198</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
