Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-6196

Опубликовано: 17 июн. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 5.5

Описание

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service.

РелизСтатусПримечание
devel

not-affected

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

jammy

needs-triage

noble

needs-triage

oracular

ignored

end of life, was needs-triage
plucky

not-affected

0.7.3-1
questing

not-affected

Показывать по

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
4 месяца назад

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service.

CVSS3: 5.5
nvd
4 месяца назад

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service.

CVSS3: 5.5
debian
4 месяца назад

A flaw was found in libgepub, a library used to read EPUB files. The s ...

suse-cvrf
3 месяца назад

Security update for libgepub

suse-cvrf
4 месяца назад

Security update for libgepub

5.5 Medium

CVSS3