CVE-2025-14933

EUVD-2025-204813
NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of NC variables. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27266.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 29.16%
Affected Products (NVD)
VendorProductVersion
unidatanetcdf
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netcdf
bookworm
postponed
bullseye
postponed
forky
1:4.10.1-1
fixed
sid
1:4.10.1-1
fixed
trixie
no-dsa
netcdf-parallel
bookworm
postponed
bullseye
postponed
forky
1:4.10.1-1
fixed
sid
1:4.10.1-2
fixed
trixie
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netcdf
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
plucky
ignored
questing
ignored
resolute
deferred
trusty
deferred
xenial
ignored
netcdf-parallel
focal
deferred
jammy
deferred
noble
deferred
plucky
ignored
questing
ignored
resolute
deferred