CVE-2025-2173 | libzvbi up to 0.2.43 src/conv.c vbi_strndup_iconv_ucs2 src_length uninitialized pointer (GHSA-g7cg-7gw9-v8cf)
A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The manipulation of the argument src_length leads to uninitialized pointer.
This vulnerability is traded as CVE-2025-2173. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.