CVE-2025-0725

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Feb 5, 2025
Updated: Feb 6, 2025

Summary

CVE-2025-0725 is a vulnerability affecting libcurl when using zlib 1.2.0.3 or older for automatic gzip decompression of content-encoded HTTP responses. An attacker can exploit an integer overflow, resulting in a buffer overflow, allowing unintended code execution. This issue poses a significant risk to systems that rely on libcurl for HTTP communications and have not applied the necessary patch. Updating zlib to a version free from this vulnerability is recommended to minimize exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share