Vulnerability Description
A vulnerability has been found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_include_common of the file /src/ucl_util.c. Such manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/user-attachments/files/22317650/poc.zip
- https://github.com/vstakhov/libucl/issues/337
- https://vuldb.com/?ctiid.325953
- https://vuldb.com/?id.325953
- https://vuldb.com/?submit.654068
FAQ
What is CVE-2025-11010?
CVE-2025-11010 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability has been found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_include_common of the file /src/ucl_util.c. Such manipulation leads to heap-based buff...
How severe is CVE-2025-11010?
CVE-2025-11010 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11010?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.