• CVE-2025-2175

发布时间: 2025年3月29日

修改时间: 2025年4月3日

概要

A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the function _vbi_strndup_iconv. The manipulation leads to integer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.

CVSS v3 指标

NVD openEuler
Confidentiality None
Attack Vector Network
CVSS评分 N/A 4.3
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity None
User Interaction Required
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2463 zvbi security update 2025年5月1日

影响产品

产品 状态
V6 zvbi Fixed
KY3.5.3 zvbi Fixed