Oval Definition:oval:org.opensuse.security:def:1206
Revision Date:2022-06-08Version:1
Title:Security update for hdf5 (Important)
Description:

This update for hdf5 fixes the following issues:

Security issues fixed:

- CVE-2020-10811: Fixed heap-based buffer over-read in the function H5O__layout_decode() located in H5Olayout.c (bsc#1167405). - CVE-2020-10810: Fixed NULL pointer dereference in the function H5AC_unpin_entry() located in H5AC.c (bsc#1167401). - CVE-2020-10809: Fixed heap-based buffer overflow in the function Decompress() located in decompress.c (bsc#1167404). - CVE-2018-17438: Fixed SIGFPE signal raise in the function H5D__select_io() of H5Dselect.c (bsc#1109570). - CVE-2018-17437: Fixed memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c. (bsc#1109569). - CVE-2018-17436: Fixed issue in ReadCode() in decompress.c that allowed attackers to cause a denial of service via a crafted HDF5 file (bsc#1109568). - CVE-2018-17434: Fixed SIGFPE signal raise in function apply_filters() of h5repack_filters.c (bsc#1109566). - CVE-2018-17433: Fixed heap-based buffer overflow in ReadGifImageDesc() in gifread.c (bsc#1109565). - CVE-2018-17432: Fixed NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c (bsc#1109564). - CVE-2018-17237: Fixed SIGFPE signal raise in the function H5D__chunk_set_info_real() (bsc#1109168). - CVE-2018-17234: Fixed memory leak in the H5O__chunk_deserialize() function in H5Ocache.c (bsc#1109167). - CVE-2018-14460: Fixed heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c (bsc#1102175). - CVE-2018-14033: Fixed heap-based buffer over-read in the function H5O_layout_decode in H5Olayout.c (bsc#1101471). - CVE-2018-14032: Fixed heap-based buffer over-read in the function H5O_fill_new_decode in H5Ofill.c (bsc#1101474). - CVE-2018-11206: Fixed out of bounds read in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c (bsc#1093657).

Bugfixes:

- Fix python-h5py packages built against out-of-date version of HDF5 (bsc#1196682). - Fix netcdf-cxx4 packages built against out-of-date version of HDF5 (bsc#1179521).
Family:unixClass:patch
Status:Reference(s):1046303
1046305
1046306
1046307
1046540
1046542
1046543
1048129
1050242
1050252
1050529
1050536
1050538
1050545
1050549
1050662
1051510
1052766
1055968
1056427
1056643
1056651
1056653
1056657
1056658
1056662
1056686
1056787
1058115
1058513
1058659
1058717
1060463
1061024
1061840
1062897
1064802
1065600
1066110
1066129
1068032
1068054
1071218
1071995
1072829
1072856
1073513
1073765
1073960
1074562
1074578
1074701
1074741
1074873
1074919
1075006
1075007
1075262
1075419
1075748
1075876
1076049
1076115
1076372
1076830
1077338
1078248
1078353
1079152
1079747
1080039
1080542
1081599
1082485
1082504
1082869
1082962
1083647
1083900
1084001
1084570
1085308
1085539
1085626
1085933
1085936
1085937
1085938
1085939
1085941
1086282
1086283
1086286
1086288
1086319
1086323
1086400
1086652
1086739
1087078
1087082
1087084
1087092
1087205
1087210
1087213
1087214
1087284
1087405
1087458
1087939
1087978
1088354
1088690
1088704
1088722
1088796
1088804
1088821
1088866
1089115
1089268
1089467
1089608
1089663
1089664
1089667
1089669
1089752
1089753
1089878
1090150
1090457
1090605
1090643
1090646
1090658
1090734
1090888
1090953
1091158
1091171
1091424
1091594
1091666
1091678
1091686
1091781
1091782
1091815
1091860
1091960
1092100
1092472
1092710
1092772
1092888
1092904
1092975
1093023
1093027
1093035
1093118
1093148
1093158
1093184
1093205
1093273
1093290
1093604
1093641
1093649
1093653
1093655
1093657
1093663
1093721
1093728
1093904
1093990
1094244
1094356
1094420
1094541
1094575
1094751
1094825
1094840
1094912
1094978
1095042
1095094
1095115
1095155
1095265
1095321
1095337
1095467
1095573
1095735
1095893
1096065
1096480
1096529
1096696
1096705
1096728
1096753
1096790
1096793
1097034
1097105
1097234
1097356
1097373
1097439
1097465
1097468
1097470
1097471
1097472
1097551
1097780
1097796
1097800
1097941
1097961
1098016
1098043
1098050
1098174
1098176
1098236
1098401
1098425
1098435
1098599
1098626
1098706
1098983
1098995
1099029
1099041
1099109
1099142
1099183
1099715
1099792
1099918
1099924
1099966
1100132
1100209
1100340
1100362
1100382
1100394
1100416
1100418
1100491
1100602
1100633
1100843
1101296
1101315
1101324
1101471
1101474
1102175
1109167
1109168
1109564
1109565
1109566
1109568
1109569
1109570
1167401
1167404
1167405
1179521
1196682
971975
975772
CVE-2017-5715
CVE-2017-5715
CVE-2017-5753
CVE-2017-5753
CVE-2018-1000200
CVE-2018-1000200
CVE-2018-1000204
CVE-2018-1000204
CVE-2018-10087
CVE-2018-10087
CVE-2018-10124
CVE-2018-10124
CVE-2018-1092
CVE-2018-1092
CVE-2018-1093
CVE-2018-1093
CVE-2018-1094
CVE-2018-1094
CVE-2018-1118
CVE-2018-1118
CVE-2018-1120
CVE-2018-1120
CVE-2018-11206
CVE-2018-1130
CVE-2018-1130
CVE-2018-12233
CVE-2018-12233
CVE-2018-13053
CVE-2018-13053
CVE-2018-13405
CVE-2018-13405
CVE-2018-13406
CVE-2018-13406
CVE-2018-14032
CVE-2018-14033
CVE-2018-14460
CVE-2018-17234
CVE-2018-17237
CVE-2018-17432
CVE-2018-17433
CVE-2018-17434
CVE-2018-17436
CVE-2018-17437
CVE-2018-17438
CVE-2018-3639
CVE-2018-3639
CVE-2018-5803
CVE-2018-5803
CVE-2018-5848
CVE-2018-5848
CVE-2018-7492
CVE-2018-7492
CVE-2018-8781
CVE-2018-8781
CVE-2018-9385
CVE-2018-9385
CVE-2019-7572
CVE-2019-7573
CVE-2019-7574
CVE-2019-7575
CVE-2019-7576
CVE-2019-7577
CVE-2019-7578
CVE-2019-7635
CVE-2019-7636
CVE-2019-7637
CVE-2019-7638
CVE-2020-10809
CVE-2020-10810
CVE-2020-10811
CVE-2020-14019
SUSE-SU-2018:2092-1
SUSE-SU-2022:1912-1
Platform(s):openSUSE Leap 42.1
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5
SUSE Linux Enterprise Build System Kit 12
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 15 SP3
SUSE Linux Enterprise High Availability 15
SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise Module for Basesystem 15
SUSE Linux Enterprise Module for Basesystem 15 SP3
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Module for High Performance Computing 15 SP3
SUSE Linux Enterprise Module for Legacy Software 15
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
SUSE Linux Enterprise Module for Server Applications 15
SUSE Linux Enterprise Module for Web Scripting 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Software Development Kit 11 SP3
SUSE Linux Enterprise Software Development Kit 12 SP1
SUSE Linux Enterprise Software Development Kit 12 SP2
SUSE Linux Enterprise Workstation Extension 12
SUSE Linux Enterprise Workstation Extension 12 SP1
SUSE Linux Enterprise Workstation Extension 15
SUSE Manager Proxy 4.2
SUSE Manager Server 4.2
SUSE Package Hub for SUSE Linux Enterprise 15
Product(s):
Definition Synopsis
  • SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5 is installed
  • AND Package Information
  • openstack-cinder-2014.2.3.dev13-1 is installed
  • OR openstack-cinder-volume-2014.2.3.dev13-1 is installed
  • OR python-cinder-2014.2.3.dev13-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND coolkey-1.1.0-147 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • MozillaFirefox-38.4.0esr-51 is installed
  • OR MozillaFirefox-translations-38.4.0esr-51 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • DirectFB-1.7.1-6 is installed
  • OR lib++dfb-1_7-1-1.7.1-6 is installed
  • OR libdirectfb-1_7-1-1.7.1-6 is installed
  • OR libdirectfb-1_7-1-32bit-1.7.1-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
  • AND Package Information
  • python-rtslib-fb-common-2.1.74-1.29 is installed
  • OR python3-rtslib-fb-2.1.74-1.29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND Package Information
  • drbd-9.0.13+git.b83ade31-3.2 is installed
  • OR drbd-kmp-default-9.0.13+git.b83ade31_k4.12.14_23-3.2 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
  • OR SUSE Linux Enterprise Module for High Performance Computing 15 SP3 is installed
  • AND Package Information
  • hdf5-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR hdf5-gnu-hpc-devel-1.10.8-150300.4.3.1 is installed
  • OR hdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR hdf5-gnu-mpich-hpc-devel-1.10.8-150300.4.3.2 is installed
  • OR hdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR hdf5-gnu-mvapich2-hpc-devel-1.10.8-150300.4.3.1 is installed
  • OR hdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR hdf5-gnu-openmpi3-hpc-devel-1.10.8-150300.4.3.2 is installed
  • OR hdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR hdf5-gnu-openmpi4-hpc-devel-1.10.8-150300.4.3.2 is installed
  • OR hdf5-hpc-examples-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-hpc-devel-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-hpc-devel-static-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-hpc-module-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-mpich-hpc-devel-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-mpich-hpc-devel-static-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-mpich-hpc-module-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-mvapich2-hpc-devel-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-mvapich2-hpc-devel-static-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-mvapich2-hpc-module-1.10.8-150300.4.3.1 is installed
  • OR hdf5_1_10_8-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-openmpi3-hpc-devel-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-openmpi3-hpc-devel-static-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-openmpi3-hpc-module-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-openmpi4-hpc-devel-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-openmpi4-hpc-devel-static-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-gnu-openmpi4-hpc-module-1.10.8-150300.4.3.2 is installed
  • OR hdf5_1_10_8-hpc-examples-1.10.8-150300.4.3.1 is installed
  • OR libhdf5-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_1_10_8-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_1_10_8-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_1_10_8-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_1_10_8-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_1_10_8-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_cpp-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_cpp_1_10_8-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_cpp_1_10_8-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_cpp_1_10_8-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_cpp_1_10_8-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_cpp_1_10_8-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_fortran-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_fortran_1_10_8-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_fortran_1_10_8-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_fortran_1_10_8-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_fortran_1_10_8-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_fortran_1_10_8-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_1_10_8-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl_1_10_8-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_1_10_8-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl_1_10_8-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_1_10_8-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_cpp-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_cpp_1_10_8-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl_cpp_1_10_8-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_cpp_1_10_8-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl_cpp_1_10_8-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_cpp_1_10_8-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_fortran-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5_hl_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5_hl_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5hl_fortran_1_10_8-gnu-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5hl_fortran_1_10_8-gnu-mpich-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5hl_fortran_1_10_8-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 is installed
  • OR libhdf5hl_fortran_1_10_8-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 is installed
  • OR libhdf5hl_fortran_1_10_8-gnu-openmpi4-hpc-1.10.8-150300.4.3.2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 is installed
  • AND Package Information
  • kernel-default-4.12.14-25.3 is installed
  • OR kernel-default-devel-4.12.14-25.3 is installed
  • OR kernel-default-man-4.12.14-25.3 is installed
  • OR kernel-devel-4.12.14-25.3 is installed
  • OR kernel-macros-4.12.14-25.3 is installed
  • OR kernel-source-4.12.14-25.3 is installed
  • OR kernel-zfcpdump-4.12.14-25.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • libSDL-1_2-0-1.2.15-3.9 is installed
  • OR libSDL-devel-1.2.15-3.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Legacy Software 15 is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.171-3.3 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.171-3.3 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.171-3.3 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.171-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • libmunge2-0.5.13-4.3 is installed
  • OR libmunge2-32bit-0.5.13-4.3 is installed
  • OR munge-0.5.13-4.3 is installed
  • OR munge-devel-0.5.13-4.3 is installed
  • OR munge-devel-32bit-0.5.13-4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 is installed
  • AND Package Information
  • krb5-1.15.2-6.6 is installed
  • OR krb5-plugin-kdb-ldap-1.15.2-6.6 is installed
  • OR krb5-server-1.15.2-6.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Web Scripting 15 is installed
  • AND Package Information
  • tomcat-9.0.12-3.8 is installed
  • OR tomcat-admin-webapps-9.0.12-3.8 is installed
  • OR tomcat-el-3_0-api-9.0.12-3.8 is installed
  • OR tomcat-jsp-2_3-api-9.0.12-3.8 is installed
  • OR tomcat-lib-9.0.12-3.8 is installed
  • OR tomcat-servlet-4_0-api-9.0.12-3.8 is installed
  • OR tomcat-webapps-9.0.12-3.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 is installed
  • AND Package Information
  • cron-4.2-55 is installed
  • OR cronie-1.4.11-55 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • libpython3_4m1_0-3.4.1-12.1 is installed
  • OR python3-base-3.4.1-12.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 is installed
  • AND enigmail-2.0.8-3.10 is installed
  • Definition Synopsis
  • SUSE Package Hub for SUSE Linux Enterprise 15 is installed
  • AND pdns-recursor-4.1.2-bp150.2.3 is installed
  • BACK