CNNVD-202512-4093 Information
Dec 23, 2025
cve
CNNVD ID
CNNVD-202512-4093
Related CVE
- CNNVD Published: 2025-12-23
Description (Chinese)
NSF Unidata NetCDF-C是美国NSF Unidata公司的一个处理NetCDF文件的工具。 NSF Unidata NetCDF-C存在安全漏洞,该漏洞源于解析变量名时缺乏对用户提供数据长度的验证,可能导致栈缓冲区溢出和远程代码执行。
Description (English)
NSF Unidata NetCDF-C is a tool for the processing of NetCDF documents by the United States company NSF Unidata. There is a security loophole in the NSF Unidata NetCDF-C, which stems from the lack of validation of data length provided by users when deciphering variable names, which could lead to spilling out of the fence and remote code execution.
Hazard Level
Medium
Vulnerability Type
其他
Affected Vendor
NSF Unidata
Published
2025-12-23
Last Modified
2026-02-24
References
https://www.zerodayinitiative.com/advisories/ZDI-25-1152/
Share on: