CVE-2025-10995 MEDIUM

CVE-2025-10995: Open Babel zipstreamimpl.h underflow memory corruption

Vendor N/A
Product Open Babel
Weakness CWE-119
Published September 26, 2025
Last update September 26, 2025

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A security vulnerability has been detected in Open Babel up to 3.1.1. This vulnerability affects the function zlib_stream::basic_unzip_streambuf::underflow in the library /src/zipstreamimpl.h. Such manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used.

Key dates

02Disclosure timeline

September 26, 2025 CVE published
September 26, 2025 Record updated