CVE-2025-2174 is an integer overflow vulnerability in the vbi_strndup_iconv_ucs2 function within the libzvbi library (up to version 0.2.43), affecting products like zapping_vbi and zvbi. This high-severity vulnerability (CVSS 7.5) can be exploited remotely without user interaction, potentially leading to a denial of service. While a public exploit has been disclosed, there is currently no evidence of active exploitation, and it has received minimal community discussion or media coverage. Upgrading to libzvbi version 0.2.44 is recommended to mitigate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.44CPE matchmatch criteria | cpe:2.3:a:zapping-vbi:zvbi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.