A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the function _vbi_strndup_iconv. The manipulation leads to integer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.
History

Fri, 03 Oct 2025 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Zapping-vbi
Zapping-vbi zvbi
CPEs cpe:2.3:a:zapping-vbi:zvbi:*:*:*:*:*:*:*:*
Vendors & Products Zapping-vbi
Zapping-vbi zvbi

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00059}

epss

{'score': 0.0009}


Tue, 11 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the function _vbi_strndup_iconv. The manipulation leads to integer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.
Title libzvbi _vbi_strndup_iconv integer overflow
Weaknesses CWE-189
CWE-190
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-11T17:13:11.689Z

Reserved: 2025-03-10T17:27:00.680Z

Link: CVE-2025-2175

cve-icon Vulnrichment

Updated: 2025-03-11T17:13:03.088Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-11T07:15:37.440

Modified: 2025-10-03T00:23:24.997

Link: CVE-2025-2175

cve-icon Redhat

No data.