Heap Buffer Over-read in ugrep Affects Data Processing Capabilities
CVE-2025-15614
4.8MEDIUM
What is CVE-2025-15614?
The ugrep tool prior to version 7.6.0 is vulnerable to a heap buffer over-read when processing maliciously crafted .Z archive files. Attackers can exploit this vulnerability by supplying malformed files, which causes the decompressor to read beyond the allocated heap buffer, leading to potential application crashes. This issue was highlighted in GitHub Issue #511 and has been addressed in subsequent updates. Users are strongly advised to upgrade to version 7.6.0 or later to mitigate this risk.
Affected Version(s)
ugrep 0 < 7.6.0
