cvelist/2025/2xxx/CVE-2025-2176.json
2025-03-11 08:01:37 +00:00

301 lines
14 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2025-2176",
"ASSIGNER": "cna@vuldb.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim_load_caption of the file src/io-sim.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The identifier of the patch is ca1672134b3e2962cd392212c73f44f8f4cb489f. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional."
},
{
"lang": "deu",
"value": "Es wurde eine Schwachstelle in libzvbi bis 0.2.43 entdeckt. Sie wurde als kritisch eingestuft. Es betrifft die Funktion vbi_capture_sim_load_caption der Datei src/io-sim.c. Mittels dem Manipulieren mit unbekannten Daten kann eine integer overflow-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung. Ein Aktualisieren auf die Version 0.2.44 vermag dieses Problem zu l\u00f6sen. Der Patch wird als ca1672134b3e2962cd392212c73f44f8f4cb489f bezeichnet. Als bestm\u00f6gliche Massnahme wird das Einspielen eines Upgrades empfohlen."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Integer Overflow",
"cweId": "CWE-190"
}
]
},
{
"description": [
{
"lang": "eng",
"value": "Numeric Error",
"cweId": "CWE-189"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "libzvbi",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "0.2.0"
},
{
"version_affected": "=",
"version_value": "0.2.1"
},
{
"version_affected": "=",
"version_value": "0.2.2"
},
{
"version_affected": "=",
"version_value": "0.2.3"
},
{
"version_affected": "=",
"version_value": "0.2.4"
},
{
"version_affected": "=",
"version_value": "0.2.5"
},
{
"version_affected": "=",
"version_value": "0.2.6"
},
{
"version_affected": "=",
"version_value": "0.2.7"
},
{
"version_affected": "=",
"version_value": "0.2.8"
},
{
"version_affected": "=",
"version_value": "0.2.9"
},
{
"version_affected": "=",
"version_value": "0.2.10"
},
{
"version_affected": "=",
"version_value": "0.2.11"
},
{
"version_affected": "=",
"version_value": "0.2.12"
},
{
"version_affected": "=",
"version_value": "0.2.13"
},
{
"version_affected": "=",
"version_value": "0.2.14"
},
{
"version_affected": "=",
"version_value": "0.2.15"
},
{
"version_affected": "=",
"version_value": "0.2.16"
},
{
"version_affected": "=",
"version_value": "0.2.17"
},
{
"version_affected": "=",
"version_value": "0.2.18"
},
{
"version_affected": "=",
"version_value": "0.2.19"
},
{
"version_affected": "=",
"version_value": "0.2.20"
},
{
"version_affected": "=",
"version_value": "0.2.21"
},
{
"version_affected": "=",
"version_value": "0.2.22"
},
{
"version_affected": "=",
"version_value": "0.2.23"
},
{
"version_affected": "=",
"version_value": "0.2.24"
},
{
"version_affected": "=",
"version_value": "0.2.25"
},
{
"version_affected": "=",
"version_value": "0.2.26"
},
{
"version_affected": "=",
"version_value": "0.2.27"
},
{
"version_affected": "=",
"version_value": "0.2.28"
},
{
"version_affected": "=",
"version_value": "0.2.29"
},
{
"version_affected": "=",
"version_value": "0.2.30"
},
{
"version_affected": "=",
"version_value": "0.2.31"
},
{
"version_affected": "=",
"version_value": "0.2.32"
},
{
"version_affected": "=",
"version_value": "0.2.33"
},
{
"version_affected": "=",
"version_value": "0.2.34"
},
{
"version_affected": "=",
"version_value": "0.2.35"
},
{
"version_affected": "=",
"version_value": "0.2.36"
},
{
"version_affected": "=",
"version_value": "0.2.37"
},
{
"version_affected": "=",
"version_value": "0.2.38"
},
{
"version_affected": "=",
"version_value": "0.2.39"
},
{
"version_affected": "=",
"version_value": "0.2.40"
},
{
"version_affected": "=",
"version_value": "0.2.41"
},
{
"version_affected": "=",
"version_value": "0.2.42"
},
{
"version_affected": "=",
"version_value": "0.2.43"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://vuldb.com/?id.299205",
"refsource": "MISC",
"name": "https://vuldb.com/?id.299205"
},
{
"url": "https://vuldb.com/?ctiid.299205",
"refsource": "MISC",
"name": "https://vuldb.com/?ctiid.299205"
},
{
"url": "https://vuldb.com/?submit.512802",
"refsource": "MISC",
"name": "https://vuldb.com/?submit.512802"
},
{
"url": "https://github.com/zapping-vbi/zvbi/security/advisories/GHSA-g7cg-7gw9-v8cf",
"refsource": "MISC",
"name": "https://github.com/zapping-vbi/zvbi/security/advisories/GHSA-g7cg-7gw9-v8cf"
},
{
"url": "https://github.com/zapping-vbi/zvbi/commit/ca1672134b3e2962cd392212c73f44f8f4cb489f",
"refsource": "MISC",
"name": "https://github.com/zapping-vbi/zvbi/commit/ca1672134b3e2962cd392212c73f44f8f4cb489f"
},
{
"url": "https://github.com/zapping-vbi/zvbi/releases/tag/v0.2.44",
"refsource": "MISC",
"name": "https://github.com/zapping-vbi/zvbi/releases/tag/v0.2.44"
}
]
},
"credits": [
{
"lang": "en",
"value": "ninpwn (VulDB User)"
}
],
"impact": {
"cvss": [
{
"version": "3.1",
"baseScore": 7.3,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseSeverity": "HIGH"
},
{
"version": "3.0",
"baseScore": 7.3,
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseSeverity": "HIGH"
},
{
"version": "2.0",
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
}
]
}
}