Vulnerability Description
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Hci Baseboard Management Controller | - |
| Netapp | Hci H610S Firmware | - |
| Netapp | Hci H610S | - |
| Netapp | Hci H610C Firmware | - |
| Netapp | Hci H610C | - |
| Netapp | Hci H615C Firmware | - |
| Netapp | Hci H615C | - |
| Netapp | Solidfire \& Hci Management Node | - |
| Netapp | Solidfire \& Hci Storage Node | - |
| Haxx | Curl | >= 7.10.5, < 8.12.0 |
| Haxx | Libcurl | >= 7.10.5, < 8.12.0 |
| Zlib | Zlib | <= 1.2.0.3 |
Related Weaknesses (CWE)
References
- https://curl.se/docs/CVE-2025-0725.htmlVendor Advisory
- https://curl.se/docs/CVE-2025-0725.jsonVendor Advisory
- https://hackerone.com/reports/2956023ExploitIssue Tracking
- http://www.openwall.com/lists/oss-security/2025/02/05/3Mailing List
- http://www.openwall.com/lists/oss-security/2025/02/06/2Mailing List
- http://www.openwall.com/lists/oss-security/2025/02/06/4Mailing List
- https://github.com/curl/curl/commit/76f83f0db23846e254d940ec7Patch
- https://security.netapp.com/advisory/ntap-20250306-0009/Third Party Advisory
FAQ
What is CVE-2025-0725?
CVE-2025-0725 is a vulnerability with a CVSS score of 7.3 (HIGH). When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integ...
How severe is CVE-2025-0725?
CVE-2025-0725 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0725?
Check the references section above for vendor advisories and patch information. Affected products include: Netapp Hci Baseboard Management Controller, Netapp Hci H610S Firmware, Netapp Hci H610S, Netapp Hci H610C Firmware, Netapp Hci H610C.