CVE-2025-2175 Details
Description
A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the function _vbi_strndup_iconv. The manipulation leads to integer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.
A vulnerability exists in libzvbi versions through 0.2.43, specifically in the _vbi_strndup_iconv function, where improper input handling can lead to an integer overflow. This overflow may cause a heap overflow, potentially allowing for a denial-of-service condition or other impacts. The vulnerability can be exploited remotely and requires user interaction.
Users are advised to upgrade to libzvbi version 0.2.44, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zapping-vbi/zvbi/releases/tag/v0.2.44 | [email protected] | Release Notes |
| https://github.com/zapping-vbi/zvbi/security/advisories/GHSA-g7cg-7gw9-v8cf | [email protected] | PatchVendor Advisory |
| https://vuldb.com/?ctiid.299204 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.299204 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.512801 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
| CWE-189 | Numeric Errors | [email protected] |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zapping-vbi zvbi | < 0.2.44 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 3, 2025 | Initial Analysis | [email protected] |
| Mar 11, 2025 | New CVE Received | [email protected] |