CVE-2025-0633: Heap Overflow in iniparser.c
Published Feb 19, 2025
·Updated
Heap Overflow in iniparser.c
Other sources
Heap-based Buffer Overflow vulnerability in iniparserdumpsectionini() in iniparser allows attacker to read out of bound memory
— NVD
Affected Software
4 affected componentsFixes available
iniparser iniparser<4.2.6
debian/iniparser<=4.1-4, <=4.1-6
4.2.6-1
Microsoft azl3 iniparser 4.1-8
Microsoft azl3 iniparser 4.1-9
Event History
Feb 19, 2025
CVE Published
via MITRE·07:01 AM
Data Sourced
via MITRE·07:01 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Feb 28, 2025
Data Sourced
via Ubuntu·06:57 PM
RemedyDescriptionSeverityAffected Software
Mar 13, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-0633?
CVE-2025-0633 is considered a high severity vulnerability due to its potential for heap-based buffer overflow exploitation.
2
How do I fix CVE-2025-0633?
To mitigate CVE-2025-0633, upgrade iniparser to version 4.2.6 or later.
3
What is affected by CVE-2025-0633?
CVE-2025-0633 affects iniparser versions prior to 4.2.6.
4
What type of vulnerability is CVE-2025-0633?
CVE-2025-0633 is a heap-based buffer overflow vulnerability.
5
What can an attacker do with CVE-2025-0633?
An attacker can exploit CVE-2025-0633 to read out-of-bounds memory, potentially leading to sensitive data exposure.