PT-2025-21223 · Unknown+1 · Pointcloudlibrary+1

Titan Team

·

Published

2025-05-14

·

Updated

2025-12-28

·

CVE-2025-4638

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PointCloudLibrary (PCL) versions prior to 1.14.0
Description: A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic.
Recommendations: For PCL versions prior to 1.14.0, update to version 1.14.0 or later to use the system's zlib installation by default, which mitigates this issue. Alternatively, ensure that the system's zlib library is up to date. As a temporary workaround, consider restricting the use of the inftrees.c component until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-4638
MGASA-2025-0162
ROSA-SA-2025-2896

Affected Products

Pointcloudlibrary
Zlib