Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 2025-0121: zvbi Security Advisory Updates

mageia
Calendar Grey March 31, 2025
Dist Mageia Esm H88
Mageia's security advisory addresses critical vulnerabilities in libzvbi that may allow remote attacks. Upgrade is crucial!
A vulnerability was found in libzvbi up to 0.2.43

Summary

A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The manipulation of the argument src_length leads to uninitialized pointer. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue (CVE-2025-2173). A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim_load_caption of the file src/io-sim.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue(A vulnerability classified as critical has been found in libzvbi up to 0.2.43. This affects the function vbi_capture_sim_load_caption of the file src/io-sim.c. The manipulation leads to integer overflow. ...

References

- https://bugs.mageia.org/show_bug.cgi?id=34136

- https://ubuntu.com/security/notices/USN-7367-1

- https://www.cve.org/CVERecord?id=CVE-2025-2173

- https://www.cve.org/CVERecord?id=CVE-2025-2174

- https://www.cve.org/CVERecord?id=CVE-2025-2175

- https://www.cve.org/CVERecord?id=CVE-2025-2176

- https://www.cve.org/CVERecord?id=CVE-2025-2177

Resolution

SRPMS

- 9/core/zvbi-0.2.44-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 31 Mar 2025
URL: https://advisories.mageia.org/MGASA-2025-0121.html
Type: security
CVE: CVE-2025-2173, CVE-2025-2174, CVE-2025-2175, CVE-2025-2176, CVE-2025-2177

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here