We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-7208

9fans plan9port x509.c edump heap-based overflow



Description

EN DE

A vulnerability was found in 9fans plan9port up to 9da5b44. It has been classified as critical. This affects the function edump in the library /src/plan9port/src/libsec/port/x509.c. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is b3e06559475b0130a7a2fb56ac4d131d13d2012f. It is recommended to apply a patch to fix this issue.

Es wurde eine Schwachstelle in 9fans plan9port bis 9da5b44 ausgemacht. Sie wurde als kritisch eingestuft. Dabei betrifft es die Funktion edump in der Bibliothek /src/plan9port/src/libsec/port/x509.c. Durch die Manipulation mit unbekannten Daten kann eine heap-based buffer overflow-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung. Dieses Produkt setzt Rolling Releases ein. Aus diesem Grund sind Details zu betroffenen oder zu aktualisierende Versionen nicht verfügbar. Der Patch wird als b3e06559475b0130a7a2fb56ac4d131d13d2012f bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.

Reserved 2025-07-07 | Published 2025-07-09 | Updated 2025-07-09 | Assigner VulDB


MEDIUM: 5.1CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
MEDIUM: 5.5CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
MEDIUM: 5.5CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
5.2AV:A/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Problem types

Heap-based Buffer Overflow

Memory Corruption

Product status

9da5b44
affected

Timeline

2024-04-02:Advisory disclosed
2024-04-02:VulDB entry created
2025-07-07:VulDB entry last update

References

vuldb.com/?id.259053 (VDB-259053 | 9fans plan9port x509.c edump heap-based overflow) vdb-entry technical-description

vuldb.com/?ctiid.259053 (VDB-259053 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.304567 (Submit #304567 | plan9port plan9port commit be7c68f6954f7dcaa53403e0f600716f65a13d32 heap-buffer-overflow) third-party-advisory

vuldb.com/?submit.607684 (Submit #607684 | 9fans plan9port plan9port-20250329 (commit 9da5b44) Heap-based Buffer Overflow (Duplicate)) third-party-advisory

drive.google.com/...NLNDiFQB2OAp7S-ZKYoF7nxfIZGO?usp=sharing related

github.com/9fans/plan9port/issues/710 issue-tracking

github.com/...tachments/files/19698345/plan9port_crash_1.txt exploit

git.9front.org/...5b0130a7a2fb56ac4d131d13d2012f/commit.html patch

cve.org (CVE-2025-7208)

nvd.nist.gov (CVE-2025-7208)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-7208

Support options

Helpdesk Chat, Email, Knowledgebase