CVE-2025-2174

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 476

Summary

CVE-2025-2174 is a recently disclosed vulnerability affecting libzvbi up to version 0.2.43. This issue lies within the function vbi_strndup_iconv_ucs2 in src/conv.c, where an integer overflow can occur due to the manipulation of the src_length argument. This vulnerability can be exploited remotely, and the exploit has already been made public. To mitigate this risk, upgrading to libzvbi version 0.2.44 is recommended. The patch for this issue is named ca1673134b3e2962cd392212c73f44f8f4cb489f. The code maintainer was notified and responded promptly with a professional approach to address the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share