CVE-2025-48172: Integer Overflow
Published Jul 4, 2025
·Updated
CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chmlib.c chmdecompressblock integer overflow. There is a resultant heap-based buffer overflow in chmfetchbytes.
Affected Software
2 affected components
chmlib chmlib<=2bef8d0
SumatraPDF SumatraPDF
Event History
Jul 4, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-48172?
CVE-2025-48172 is classified as a critical vulnerability due to its potential to cause a heap-based buffer overflow.
2
How do I fix CVE-2025-48172?
To address CVE-2025-48172, update CHMLib to the latest version beyond 2bef8d0.
3
Which products are affected by CVE-2025-48172?
CVE-2025-48172 affects CHMLib versions up to and including 2bef8d0 and SumatraPDF.
4
What type of vulnerability is CVE-2025-48172?
CVE-2025-48172 is an integer overflow vulnerability that leads to a heap-based buffer overflow.
5
What are the potential impacts of CVE-2025-48172?
Exploitation of CVE-2025-48172 can allow attackers to execute arbitrary code or crash the affected application.