vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.
References
Link | Resource |
---|---|
https://gist.github.com/QiuYitai/6ebfa07510828a9464ba7fb948255ed5 | Exploit Third Party Advisory |
https://github.com/vkoskiv/c-ray/issues/119 | Exploit Patch |
Configurations
History
09 Jul 2025, 19:07
Type | Values Removed | Values Added |
---|---|---|
First Time |
Vkoskiv c-ray
Vkoskiv |
|
CPE | cpe:2.3:a:vkoskiv:c-ray:1.1:*:*:*:*:*:*:* | |
References | () https://gist.github.com/QiuYitai/6ebfa07510828a9464ba7fb948255ed5 - Exploit, Third Party Advisory | |
References | () https://github.com/vkoskiv/c-ray/issues/119 - Exploit, Patch |
26 Jun 2025, 18:57
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Jun 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-476 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
25 Jun 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-25 18:15
Updated : 2025-07-09 19:07
NVD link : CVE-2025-45332
Mitre link : CVE-2025-45332
CVE.ORG link : CVE-2025-45332
JSON object : View
Products Affected
vkoskiv
- c-ray
CWE
CWE-476
NULL Pointer Dereference