First published: Tue Feb 25 2025(Updated: )
A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect computation.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyr Project Manager | <=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1673 is classified as a denial of service vulnerability due to its ability to cause a crash.
To mitigate CVE-2025-1673, upgrade to a version of the Zephyr Project Manager beyond 4.0.
CVE-2025-1673 is caused by a malicious or malformed DNS packet without a payload leading to an out-of-bounds read.
CVE-2025-1673 affects all versions of Zephyr Project Manager up to and including version 4.0.
CVE-2025-1673 can be exploited through denial of service attacks that result in application crashes.