A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Jun 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service. | |
Title | Libgepub: integer overflow in libgepub's epub archive handling | |
First Time appeared |
Redhat
Redhat enterprise Linux |
|
Weaknesses | CWE-190 | |
CPEs | cpe:/o:redhat:enterprise_linux:7 | |
Vendors & Products |
Redhat
Redhat enterprise Linux |
|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-06-17T14:29:42.228Z
Updated: 2025-06-17T14:45:55.598Z
Reserved: 2025-06-17T06:50:22.606Z
Link: CVE-2025-6196

Updated: 2025-06-17T14:45:07.280Z

Status : Awaiting Analysis
Published: 2025-06-17T15:15:54.140
Modified: 2025-06-17T20:50:23.507
Link: CVE-2025-6196
