PT-2025-26577 · Vstakhov · Libucl

Jjleo

·

Published

2025-06-23

·

Updated

2025-09-18

·

CVE-2025-6499

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: vstakhov libucl versions up to 0.9.2
Description: A problematic vulnerability was found in the vstakhov libucl, affecting the function ucl parse multiline string of the file src/ucl parser.c. This vulnerability leads to a heap-based buffer overflow. The attack must be approached locally.
Recommendations: For versions up to 0.9.2, consider disabling the ucl parse multiline string function as a temporary workaround until a patch is available. Restrict access to the src/ucl parser.c file to minimize the risk of exploitation. Avoid using the vulnerable function in local operations until the issue is resolved.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-6499

Affected Products

Libucl