Heap-based Buffer Overflow in NSF Unidata NetCDF-C Allowing Remote Code Execution
CVE-2025-14935
7.8HIGH
What is CVE-2025-14935?
This vulnerability in NSF Unidata NetCDF-C arises from the improper validation of dimension name lengths during parsing. It enables remote attackers to execute arbitrary code on affected systems when users are tricked into visiting a malicious page or opening a harmful file. By exploiting this flaw, an attacker can manipulate the buffer and potentially run code within the context of the logged-in user, endangering system security. Users and administrators are encouraged to apply all relevant patches and updates immediately.
Affected Version(s)
NetCDF-C dbe0cbb9ff3f706009cf4ee011adf3e58d8a81c1
