CVE-2025-0725
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Feb 5, 2025
Updated: Feb 6, 2025
Summary
CVE-2025-0725 is a vulnerability affecting libcurl when using zlib 1.2.0.3 or older for automatic gzip decompression of content-encoded HTTP responses. An attacker can exploit an integer overflow, resulting in a buffer overflow, allowing unintended code execution. This issue poses a significant risk to systems that rely on libcurl for HTTP communications and have not applied the necessary patch. Updating zlib to a version free from this vulnerability is recommended to minimize exposure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Libcurl
Affected Vendors
- Haxx