CVE-2025-2173

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 416

Summary

CVE-2025-2173 is a recently disclosed vulnerability affecting libzvbi up to version 0.2.43. The issue lies within the vbi_strndup_iconv_ucs2 function in src/conv.c, where a manipulation of the src_length argument results in an uninitialized pointer. This vulnerability can be exploited remotely, and the exploit has already been made public. To mitigate the risk, users are advised to upgrade to version 0.2.44, which contains the patch with the identifier 8def647eea27f7fd7ad33ff79c2d6d3e39948dce. The code maintainer acted swiftly and professionally upon being informed about the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share