Ta-Lib · Ta-Lib · CVE-2025-3017
**Name of the Vulnerable Software and Affected Versions**
TA-Lib versions up to 0.6.4
**Description**
A critical issue has been found in TA-Lib, affecting the `setInputBuffer` function of the `ta regtest` component. This issue leads to an out-of-bounds write and can be exploited locally. The exploit has been disclosed publicly.
**Recommendations**
For TA-Lib versions up to 0.6.4, apply a patch to fix this issue. As a temporary workaround, consider restricting access to the `setInputBuffer` function of the `ta regtest` component until a patch is available.