CNNVD-202512-4100 Information

CNNVD ID

CNNVD-202512-4100

CVE-2025-14933

  • CNNVD Published: 2025-12-23

Description (Chinese)

NSF Unidata NetCDF-C是美国NSF Unidata公司的一个处理NetCDF文件的工具。 NSF Unidata NetCDF-C存在输入验证错误漏洞,该漏洞源于解析NC变量时缺乏对用户提供数据的验证,可能导致整数溢出和远程代码执行。

Description (English)

NSF Unidata NetCDF-C is a tool for the processing of NetCDF documents by the United States company NSF Unidata. NSF Unidata NetCDF-C has an input validation error loophole, which arises from the lack of validation of data provided by users when the NCRE variable is deciphered, which may lead to integer spills and remote code execution.

Hazard Level

Medium

Vulnerability Type

输入验证错误

Affected Vendor

NSF Unidata

Published

2025-12-23

Last Modified

2026-02-24

References

https://www.zerodayinitiative.com/advisories/ZDI-25-1151/

Share on: