CVE-2025-0725

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netapp:hci_baseboard_management_controller:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:hci_h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h610s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:hci_h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h610c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:hci_h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h615c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*

History

27 Jun 2025, 19:24

Type Values Removed Values Added
CPE cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*
First Time Zlib
Zlib zlib
References () https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7 - () https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7 - Patch

12 Jun 2025, 16:15

Type Values Removed Values Added
References
  • () https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7 -

13 May 2025, 18:35

Type Values Removed Values Added
First Time Netapp hci H615c
Netapp hci H610c
Netapp solidfire \& Hci Storage Node
Netapp hci Baseboard Management Controller
Haxx
Haxx libcurl
Netapp hci H615c Firmware
Netapp hci H610c Firmware
Netapp hci H610s
Haxx curl
Netapp
Netapp hci H610s Firmware
Netapp solidfire \& Hci Management Node
CPE cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h610s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h615c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_h610c:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:hci_baseboard_management_controller:-:*:*:*:*:*:*:*
CWE CWE-120
References () https://curl.se/docs/CVE-2025-0725.html - () https://curl.se/docs/CVE-2025-0725.html - Vendor Advisory
References () https://curl.se/docs/CVE-2025-0725.json - () https://curl.se/docs/CVE-2025-0725.json - Vendor Advisory
References () https://hackerone.com/reports/2956023 - () https://hackerone.com/reports/2956023 - Exploit, Issue Tracking
References () http://www.openwall.com/lists/oss-security/2025/02/05/3 - () http://www.openwall.com/lists/oss-security/2025/02/05/3 - Mailing List
References () http://www.openwall.com/lists/oss-security/2025/02/06/2 - () http://www.openwall.com/lists/oss-security/2025/02/06/2 - Mailing List
References () http://www.openwall.com/lists/oss-security/2025/02/06/4 - () http://www.openwall.com/lists/oss-security/2025/02/06/4 - Mailing List
References () https://security.netapp.com/advisory/ntap-20250306-0009/ - () https://security.netapp.com/advisory/ntap-20250306-0009/ - Third Party Advisory

07 Mar 2025, 01:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250306-0009/ -

06 Feb 2025, 19:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/02/06/4 -

06 Feb 2025, 11:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/02/06/2 -
Summary
  • (es) Cuando se le solicita a libcurl que realice una descompresión gzip automática de respuestas HTTP codificadas con contenido con la opción `CURLOPT_ACCEPT_ENCODING`, **usando zlib 1.2.0.3 o anterior**, un desbordamiento de entero controlado por un atacante haría que libcurl realice un desbordamiento de búfer.

05 Feb 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

05 Feb 2025, 11:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/02/05/3 -

05 Feb 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 10:15

Updated : 2025-06-27 19:24


NVD link : CVE-2025-0725

Mitre link : CVE-2025-0725

CVE.ORG link : CVE-2025-0725


JSON object : View

Products Affected

haxx

  • curl
  • libcurl

netapp

  • hci_h610s_firmware
  • hci_h615c_firmware
  • hci_h610c
  • hci_baseboard_management_controller
  • solidfire_\&_hci_storage_node
  • hci_h610s
  • solidfire_\&_hci_management_node
  • hci_h615c
  • hci_h610c_firmware

zlib

  • zlib
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')