CVE-2025-0633

NameCVE-2025-0633
DescriptionHeap-based Buffer Overflow vulnerability inĀ iniparser_dumpsection_ini() in iniparser allows attacker to read out of bound memory
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
iniparser (PTS)bullseye4.1-4vulnerable
bookworm4.1-6vulnerable
sid, trixie4.2.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iniparsersource(unstable)4.2.6-1unimportant

Notes

https://gitlab.com/iniparser/iniparser/-/issues/177
(updated) Testcase: https://gitlab.com/iniparser/iniparser/-/commit/fe09afa96cbbae09f796f797c75ff3b3e60d2e7b (v4.2.6)
Fixed by: https://gitlab.com/iniparser/iniparser/-/commit/072a39a772a38c475e35a1be311304ca99e9de7f (v4.2.6)
Doesn't cross any security boundary

Search for package or bug name: Reporting problems