CVE-2025-60751

NameCVE-2025-60751
DescriptionGeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4361-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
geographiclib (PTS)bullseye1.51-1vulnerable
bullseye (security)1.51-1+deb11u1fixed
bookworm2.1.2-1vulnerable
trixie2.5-1vulnerable
forky, sid2.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
geographiclibsourcebullseye1.51-1+deb11u1DLA-4361-1
geographiclibsource(unstable)2.5.2-1

Notes

[trixie] - geographiclib <no-dsa> (Minor issue)
[bookworm] - geographiclib <no-dsa> (Minor issue)
https://github.com/geographiclib/geographiclib/issues/43
https://github.com/zer0matt/CVE-2025-60751
https://github.com/geographiclib/geographiclib/commit/aec521dff5ec0757cdefa018b152fffcfbca3eac (v2.5.2)

Search for package or bug name: Reporting problems