When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
History

Tue, 13 May 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Haxx
Haxx curl
Haxx libcurl
Netapp
Netapp hci Baseboard Management Controller
Netapp hci H610c
Netapp hci H610c Firmware
Netapp hci H610s
Netapp hci H610s Firmware
Netapp hci H615c
Netapp hci H615c Firmware
Netapp solidfire \& Hci Management Node
Netapp solidfire \& Hci Storage Node
Weaknesses CWE-120
CPEs cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h610c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h610s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h615c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_h615c_firmware:-:*:*:*:*:*:*:*
Vendors & Products Haxx
Haxx curl
Haxx libcurl
Netapp
Netapp hci Baseboard Management Controller
Netapp hci H610c
Netapp hci H610c Firmware
Netapp hci H610s
Netapp hci H610s Firmware
Netapp hci H615c
Netapp hci H615c Firmware
Netapp solidfire \& Hci Management Node
Netapp solidfire \& Hci Storage Node

Fri, 07 Mar 2025 01:30:00 +0000

Type Values Removed Values Added
References

Fri, 07 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680
References
Metrics threat_severity

None

threat_severity

Low


Thu, 06 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
References

Thu, 06 Feb 2025 11:30:00 +0000

Type Values Removed Values Added
References

Wed, 05 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Feb 2025 11:45:00 +0000

Type Values Removed Values Added
References

Wed, 05 Feb 2025 09:30:00 +0000

Type Values Removed Values Added
Description When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
Title gzip integer overflow
References

cve-icon MITRE

Status: PUBLISHED

Assigner: curl

Published:

Updated: 2025-03-07T00:10:50.268Z

Reserved: 2025-01-27T04:58:09.514Z

Link: CVE-2025-0725

cve-icon Vulnrichment

Updated: 2025-03-07T00:10:50.268Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-05T10:15:22.980

Modified: 2025-05-13T18:35:30.150

Link: CVE-2025-0725

cve-icon Redhat

Severity : Low

Publid Date: 2025-02-05T09:18:20Z

Links: CVE-2025-0725 - Bugzilla