CVE-2025-0725
ADVISORY - debianSummary
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the CURLOPT_ACCEPT_ENCODING
option, using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
- curl 8.12.0+git20250209.89ed161+ds-1 (unimportant) https://curl.se/docs/CVE-2025-0725.html Introduced with: https://github.com/curl/curl/commit/019c4088cfcca0d2b7c5cc4f52ca5dac0c616089 (curl-7_10_5) Fixed by: https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7fe141010077eb88 (curl-8_12_0) Patch only drops officially support for zlib before 1.2.0.4 Can only be triggered when using ancient runtime zlib of version 1.2.0.3 or older
EPSS Score: 0.00215 (0.442)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Debian
CREATED
UPDATED
ADVISORY IDCVE-2025-0725
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowPackage | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
---|---|---|---|---|---|
debian/curl | deb | debian | 12 | >=7.88.1-10+deb12u12 | Not yet available |
debian/curl | deb | debian | 11 | >=7.74.0-1.3+deb11u13 | Not yet available |
debian/curl | deb | debian | unstable | <8.12.0+git20250209.89ed161+ds-1 | 8.12.0+git20250209.89ed161+ds-1 |
debian/curl | deb | debian | 13 | <8.12.0+git20250209.89ed161+ds-1 | 8.12.0+git20250209.89ed161+ds-1 |
Severity and metrics
No CVSS data available from this advisory.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2025-0725
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.3highAlpine
CREATED
UPDATED
ADVISORY IDCVE-2025-0725
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2025-0725
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowChainguard
CREATED
UPDATED
ADVISORY ID
CGA-378j-cghq-mmhg
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-