« List of all CVEs

CVE-2025-0725

gzip integer overflow

Published: 2/5/2025 Last updated: 6/12/2025 Reserved: 1/27/2025

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

CNA assigner: curl (2499f714-1537-4658-8207-48ae4bb9eae9) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.3 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Opam packages affected (3)

conf-libcurl conf-mingw-w64-curl-i686 conf-mingw-w64-curl-x86_64

Products affected (1)

Product Vendor Version
curl curl < 53fb25e90c0a503a17c639341ba5e755cb2feb5c

References (8)

Credits (2)