CVE-2025-0725

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/02/2025
Last modified:
07/03/2025

Description

When libcurl is asked to perform automatic gzip decompression of<br /> content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option,<br /> **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would<br /> make libcurl perform a buffer overflow.