CVE-2025-0725
gzip integer overflow
When libcurl is asked to perform automatic gzip decompression of
content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option,
**using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would
make libcurl perform a buffer overflow.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Productos afectados
curl · curl¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://curl.se/docs/CVE-2025-0725.htmlhttps://curl.se/docs/CVE-2025-0725.jsonhttps://github.com/curl/curl/commit/76f83f0db23846e254d940ec7https://hackerone.com/reports/2956023https://security.netapp.com/advisory/ntap-20250306-0009/http://www.openwall.com/lists/oss-security/2025/02/05/3http://www.openwall.com/lists/oss-security/2025/02/06/2http://www.openwall.com/lists/oss-security/2025/02/06/4