CVE-2025-1052
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 11, 2025
Updated: Feb 18, 2025
CWE ID 787
CWE ID 122
Summary
CVE-2025-1052 is a heap-based buffer overflow vulnerability in Mintty's sixel image parsing functionality. This issue allows remote attackers to execute arbitrary code if a user visits a malicious webpage or opens a specially crafted file. The flaw arises due to insufficient validation of user-supplied data before copying it to a heap buffer. Exploitation requires user interaction. This vulnerability, identified as ZDI-CAN-23382, can lead to significant security risks if left unaddressed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Mintty Project Mintty