CVE-2025-2177

EUVD-2025-7530
A vulnerability classified as critical was found in libzvbi up to 0.2.43. This vulnerability affects the function vbi_search_new of the file src/search.c. The manipulation of the argument pat_len leads to integer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The patch is identified as ca1672134b3e2962cd392212c73f44f8f4cb489f. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
zapping-vbizvbi
𝑥
< 0.2.44
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zvbi
bookworm
0.2.41-1+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
0.2.35-18+deb11u1
fixed
forky
0.2.44-1
fixed
sid
0.2.44-1
fixed
trixie
0.2.44-1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libzvbi0
suse enterprise server 12 SP5
0.2.35-3.3.1
fixed
zvbi-devel
suse enterprise server 12 SP5
0.2.35-3.3.1
fixed