https://seclists.org/oss-sec/2025/q1/101: [SECURITY ADVISORY] curl: CVE-2025-0725: gzip integer overflow
Published Feb 5, 2025
·Updated
Affected Software
2 affected components
curl libcurl<1.2.0.3
zlib zlib<=1.2.0.3
Frequently Asked Questions
1
What is the severity of CVE-2025-0725?
CVE-2025-0725 has been rated as a high-severity vulnerability due to its potential for integer overflow leading to application crashes or security breaches.
2
How do I fix CVE-2025-0725?
To fix CVE-2025-0725, update to the latest version of curl or libcurl that addresses this integer overflow vulnerability.
3
What systems are affected by CVE-2025-0725?
CVE-2025-0725 affects applications using libcurl for automatic gzip decompression of HTTP responses.
4
What are the potential impacts of CVE-2025-0725?
The potential impacts of CVE-2025-0725 include application crashes and exploitation opportunities for remote code execution.
5
Which libraries are associated with CVE-2025-0725?
CVE-2025-0725 is associated with the curl/libcurl and zlib libraries.