https://seclists.org/oss-sec/2025/q1/108: [SECURITY ADVISORY] curl: CVE-2025-0725: gzip integer overflow
Published Feb 6, 2025
·Updated
Affected Software
1 affected component
curl libcurl<1.0.2.4
Frequently Asked Questions
1
What is the severity of CVE-2025-0725?
CVE-2025-0725 has been identified as a critical severity vulnerability due to the potential for an integer overflow leading to denial of service.
2
How do I fix CVE-2025-0725?
To fix CVE-2025-0725, update to the latest version of curl that includes the patch for this vulnerability.
3
What versions of curl are affected by CVE-2025-0725?
CVE-2025-0725 affects versions of curl with the vulnerable code path that supports zlib versions prior to 1.0.2.4.
4
What impact does CVE-2025-0725 have on system security?
CVE-2025-0725 can potentially allow an attacker to exploit the integer overflow, leading to a denial of service condition.
5
Who reported CVE-2025-0725?
CVE-2025-0725 was reported by Fay Stegerman on February 5, 2025.