CVE-2025-0725 describes an integer overflow vulnerability in libcurl, specifically when handling automatic gzip decompression with zlib versions 1.2.0.3 or older, leading to a buffer overflow. This flaw affects products utilizing libcurl and older zlib versions, including those from haxx and netapp. Rated as HIGH severity (CVSS 7.3), it can be exploited remotely with low complexity, potentially leading to limited impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, with its presence on the CISA-alerts list being the primary media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:hci_baseboard_management_controller:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:hci_h610s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:hci_h610c_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:hci_h615c_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - November 2025
Nov 12, 2025Third-Party Package Updates in Splunk Enterprise - July 2025
Jul 7, 2025gzip integer overflow
Feb 11, 2025libcurl: Buffer Overflow in libcurl via zlib Integer Overflow
Feb 5, 2025gzip integer overflow
Feb 5, 2025