CVE-2025-2176

EUVD-2025-7529
A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim_load_caption of the file src/io-sim.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The identifier of the patch is ca1672134b3e2962cd392212c73f44f8f4cb489f. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
zapping-vbizvbi
𝑥
< 0.2.44
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zvbi
bookworm
0.2.41-1+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
0.2.35-18+deb11u1
fixed
forky
0.2.44-1
fixed
sid
0.2.44-1
fixed
trixie
0.2.44-1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libzvbi0
suse enterprise server 12 SP5
0.2.35-3.3.1
fixed
zvbi-devel
suse enterprise server 12 SP5
0.2.35-3.3.1
fixed