CVE-2025-2338: tbeu matio io.c strdup_vprintf heap-based overflow
Published Mar 16, 2025
·Updated
A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdupvprintf of the file src/io.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
tbeu matio
Matio Project Matio=1.5.28
Event History
Mar 16, 2025
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
May 20, 58462
Event
via NVD·12:24 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-2338?
CVE-2025-2338 is classified as a critical vulnerability.
2
How do I fix CVE-2025-2338?
To fix CVE-2025-2338, you should update tbeu matio to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-2338?
CVE-2025-2338 is a heap-based buffer overflow vulnerability.
4
Can CVE-2025-2338 be exploited remotely?
Yes, CVE-2025-2338 can be exploited remotely.
5
What function is affected by CVE-2025-2338?
The function affected by CVE-2025-2338 is strdup_vprintf in the file src/io.c.