• CVE-2025-2173

发布时间: 2025年3月29日

修改时间: 2025年4月3日

概要

A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The manipulation of the argument src_length leads to uninitialized pointer. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The patch is identified as 8def647eea27f7fd7ad33ff79c2d6d3e39948dce. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.

CVSS v3 指标

NVD openEuler
Confidentiality Low
Attack Vector Network
CVSS评分 N/A 5.3
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity None
User Interaction None
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2456 zvbi security update 2025年5月1日
KylinSec-SA-2025-2546 zvbi security update 2025年7月7日

影响产品

产品 状态
KY3.4-5 zvbi Fixed
V6 zvbi Fixed
KY3.5.3 zvbi Fixed
KY3.5.2 zvbi Fixed