CVE-2025-3017

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 863

Summary

CVE-2025-3017 is a critical vulnerability that affects TA-Lib versions up to 0.6.4. The issue lies in the function setInputBuffer of the file ta_test_func/test_minmax.c within the ta_regtest component. This manipulation leads to an out-of-bounds write, potentially allowing attackers to launch an attack on the local host. The exploit has been disclosed to the public, increasing the risk of exploitation. To mitigate this vulnerability, it's strongly recommended to apply patch 5879180e9070ec35d52948f2f57519713256a0f1 as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost, Inc.