https://seclists.org/oss-sec/2025/q1/110: [SECURITY ADVISORY] curl: CVE-2025-0725: gzip integer overflow
Published Feb 5, 2025
·Updated
Affected Software
2 affected components
zlib zlib<=1.2.0.3
curl libcurl>8.12.0
Frequently Asked Questions
1
What is the severity of CVE-2025-0725?
CVE-2025-0725 has been classified as a high severity vulnerability due to the potential for integer overflow leading to application crashes or arbitrary code execution.
2
What are the affected versions for CVE-2025-0725?
CVE-2025-0725 affects applications that use zlib version 1.2.0.3 or older, which can potentially exploit the integer overflow issue.
3
How do I fix CVE-2025-0725?
To fix CVE-2025-0725, update zlib to version 1.2.0.4 or newer, which does not contain the vulnerability.
4
What software is impacted by CVE-2025-0725?
CVE-2025-0725 impacts the curl and libcurl software due to their reliance on the affected versions of zlib.
5
Is there a known exploit for CVE-2025-0725?
As of now, there are no publicly known exploits for CVE-2025-0725, but the risk remains significant if the vulnerable versions are not updated.