VDB
CVE-2025-2338
CVE-2025-2338
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
EPSS 0.52% · 41.0th percentile
Risk Scores
CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS Score
0.52%
41.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| tbeu | matio | 1.5.28 |
| matio_project | matio | 1.5.28 |
Timeline
- Mar 16, 2025 CVE Published
- Mar 16, 2025 PoC Published
- Mar 17, 2025 EPSS Score
- Mar 18, 2025 Coalition ESS Score
- Mar 30, 2025 EPSS Score
- Apr 13, 2025 EPSS Score
- Apr 26, 2025 EPSS Score
- May 10, 2025 EPSS Score
- May 23, 2025 EPSS Score
- Jun 6, 2025 EPSS Score
- Jun 19, 2025 EPSS Score
- Jul 3, 2025 EPSS Score
References
- VDB-299802 | tbeu matio io.c strdup_vprintf heap-based overflow vdb
- VDB-299802 | CTI Indicators (IOB, IOC, IOA) url
- Submit #510781 | https://github.com/tbeu/matio matio 1.5.28 Heap-based Buffer Overflow third-party-advisory
- https://github.com/tbeu/matio/issues/269 issue
- https://github.com/tbeu/matio/issues/269#issue-2883920922 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-2338 advisory