CVE-2025-0725: gzip integer overflow
gzip integer overflow
Other sources
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the CURLOPTACCEPTENCODING option, using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.40-4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.42-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.40-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.11.1-3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0725?
CVE-2025-0725 has a critical severity due to the potential for an integer overflow leading to a buffer overflow.
How do I fix CVE-2025-0725?
To fix CVE-2025-0725, upgrade your libcurl to a version later than 1.2.0.3.
What versions of libcurl are affected by CVE-2025-0725?
CVE-2025-0725 affects libcurl versions 1.2.0.3 and older.
What security risks does CVE-2025-0725 pose?
CVE-2025-0725 can allow attackers to execute arbitrary code through a buffer overflow exploit.
Is it safe to use libcurl versions newer than 1.2.0.3 in relation to CVE-2025-0725?
Yes, using versions of libcurl newer than 1.2.0.3 mitigates the vulnerability identified in CVE-2025-0725.