CVE-2021-36977
CVE-2021-36977
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Jul 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based buffer overflow in H5MM_memcpy (called from H5MM_malloc and H5C_load_entry), related to use of HDF5 1.12.0.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31265https://github.com/google/oss-fuzz/issues/4999https://github.com/google/oss-fuzz-vulns/blob/main/vulns/matio/OSV-2021-440.yamlhttps://github.com/google/oss-fuzz-vulns/commit/37b781ace1b4228fc36483bb7e30c72ea9d4c3d6https://github.com/HDFGroup/hdf5/issues/272