CVE-2025-2175 is an integer overflow vulnerability in the _vbi_strndup_iconv function of libzvbi versions up to 0.2.43, affecting products like zapping_vbi and zvbi. Rated Medium (CVSS 6.5), this remotely exploitable flaw requires no privileges and could lead to high availability impact. While public exploit code exists, there is no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion. Upgrading to libzvbi 0.2.44 remediates this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.44CPE matchmatch criteria | cpe:2.3:a:zapping-vbi:zvbi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.