CVE-2025-0725

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netapp:hci_baseboard_management_controller:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:hci_h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h610s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:hci_h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h610c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:hci_h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h615c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-05 10:15

Updated : 2025-06-27 19:24


NVD link : CVE-2025-0725

Mitre link : CVE-2025-0725

CVE.ORG link : CVE-2025-0725


JSON object : View

Products Affected

zlib

  • zlib

netapp

  • hci_h615c_firmware
  • hci_h610c_firmware
  • hci_h610s
  • hci_h615c
  • solidfire_\&_hci_storage_node
  • hci_h610s_firmware
  • solidfire_\&_hci_management_node
  • hci_baseboard_management_controller
  • hci_h610c

haxx

  • curl
  • libcurl
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')