CVE-2025-0725 Unknown

CVE-2025-0725

SUSE Released: February 06, 2025 Updated: December 23, 2025 Restart Required

Description

CVE-2025-0725 When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow. The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).

Fixed Vulnerabilities 1

CVE-2025-0725 N/A 0.0 ⚠️ KEV fixed
Feb 05, 2025

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer…

Quick Info

Patch ID: CVE-2025-0725
Vendor: SUSE
Severity: Unknown
CVEs Fixed: 1
Restart: Required

Vendor

SUSE

Additional Info

advisory id: CVE-2025-0725
advisory type: Security Update
cvrf filename: cvrf-CVE-2025-0725.xml

Share