VDB
CVE-2025-2338
CVE-2025-2338
PUBLISHED
CVSS 7.5 HIGH
A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
EPSS 0.55% · 44.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.55%
44.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| tbeu | matio | 1.5.28 |
| matio_project | matio | 1.5.28 |
Timeline
- Mar 16, 2025 CVE Published
- Mar 16, 2025 PoC Published
- Mar 17, 2025 EPSS Score
- Mar 18, 2025 Coalition ESS Score
- Mar 31, 2025 EPSS Score
- Apr 14, 2025 EPSS Score
- Apr 28, 2025 EPSS Score
- May 12, 2025 EPSS Score
- May 26, 2025 EPSS Score
- Jun 9, 2025 EPSS Score
- Jun 23, 2025 EPSS Score
- Jul 7, 2025 EPSS Score
References
- https://github.com/tbeu/matio/issues/269#issue-2883920922 discussion
- https://github.com/tbeu/matio/issues/269 discussion
- VDB-299802 | tbeu matio io.c strdup_vprintf heap-based overflow vdb
- VDB-299802 | CTI Indicators (IOB, IOC, IOA) url
- Submit #510781 | https://github.com/tbeu/matio matio 1.5.28 Heap-based Buffer Overflow third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-2338 advisory