CVE-2025-0725
05.02.2025, 10:15
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
Vendor | Product | Version |
---|---|---|
haxx | curl | 7.10.5 ≤ 𝑥 < 8.12.0 |
haxx | libcurl | 7.10.5 ≤ 𝑥 < 8.12.0 |
netapp | hci_baseboard_management_controller | - |
netapp | hci_h610s_firmware | - |
netapp | hci_h610c_firmware | - |
netapp | hci_h615c_firmware | - |
netapp | solidfire_\&_hci_management_node | - |
netapp | solidfire_\&_hci_storage_node | - |
𝑥
= Vulnerable software versions

Debian Releases
References