CVE-2025-2176 Details
Description
A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim_load_caption of the file src/io-sim.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The identifier of the patch is ca1672134b3e2962cd392212c73f44f8f4cb489f. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.
A critical integer overflow vulnerability has been identified in libzvbi versions prior to 0.2.43. This vulnerability occurs in the function vbi_capture_sim_load_caption within the file src/io-sim.c. The integer overflow can be exploited remotely, leading to a heap overflow. This vulnerability has been publicly disclosed and is available for exploitation.
Users are advised to upgrade to libzvbi version 0.2.44, which addresses this vulnerability. The updated version is available on the project's GitHub release page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zapping-vbi/zvbi/commit/ca1672134b3e2962cd392212c73f44f8f4cb489f | [email protected] | Patch |
| https://github.com/zapping-vbi/zvbi/releases/tag/v0.2.44 | [email protected] | Release Notes |
| https://github.com/zapping-vbi/zvbi/security/advisories/GHSA-g7cg-7gw9-v8cf | [email protected] | Third Party Advisory |
| https://vuldb.com/?ctiid.299205 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.299205 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.512802 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
| CWE-189 | Numeric Errors | [email protected] |
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zapping-vbi zvbi | < 0.2.44 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 10, 2025 | Initial Analysis | [email protected] |
| Mar 11, 2025 | New CVE Received | [email protected] |