CVE-2025-1253 Details
Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.2.23, from 6.0.0 before 6.0.1.42, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.5c before 5.1.*.
A stack-based buffer overflow vulnerability has been identified in RTI Connext Professional Core Libraries. This vulnerability, classified as 'Classic Buffer Overflow', allows for the overflow of variables and tags. It affects multiple versions of Connext Professional, including versions 7.4.0 prior to 7.5.0, 7.0.0 prior to 7.3.0.7, 6.1.0 prior to 6.1.2.23, 6.0.0 prior to 6.0.1.42, 5.3.0 prior to 5.3.*, and 4.5c prior to 5.2.*. The vulnerability arises from a buffer copy operation that does not properly check the size of the input, leading to potential stack corruption.
To mitigate this vulnerability, it is recommended to protect access to the file system from which RTI Connext applications are loading license files. For RTI Connext Professional 7.3.0 and later, enabling the 'Security Plugins' RTPS protection can also help. Customers can request patches for other architectures by contacting RTI Support.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rti.com/vulnerabilities/#cve-2025-1253 | RTI | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | RTI |
| CWE-121 | Stack-based Buffer Overflow | RTI |
Affected Products
| Product | Versions |
|---|---|
| rti connext professional | >= 4.5c, <= 5.2.3 >= 5.3.0, <= 5.3.1.45 >= 6.0.0, <= 6.0.1.40 >= 6.1.0, < 6.1.2.23 >= 7.0.0, < 7.3.0.7 >= 7.4.0, < 7.5.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | CVE Modified | RTI |
| Jun 5, 2025 | Initial Analysis | [email protected] |
| May 8, 2025 | New CVE Received | RTI |