Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2025-18504 | A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service. | 
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to a widespread installation base, or stability. It is strongly recommended to apply the upstream patch once available.
Tue, 12 Aug 2025 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Gnome Gnome libgepub | |
| CPEs | cpe:2.3:a:gnome:libgepub:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | |
| Vendors & Products | Gnome Gnome libgepub | 
Tue, 17 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 17 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service. | |
| Title | Libgepub: integer overflow in libgepub's epub archive handling | |
| First Time appeared | Redhat Redhat enterprise Linux | |
| Weaknesses | CWE-190 | |
| CPEs | cpe:/o:redhat:enterprise_linux:7 | |
| Vendors & Products | Redhat Redhat enterprise Linux | |
| References |  | |
| Metrics | threat_severity 
 | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-09-02T19:57:50.442Z
Reserved: 2025-06-17T06:50:22.606Z
Link: CVE-2025-6196
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-06-17T14:45:07.280Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-06-17T15:15:54.140
Modified: 2025-08-12T12:48:43.230
Link: CVE-2025-6196
 Redhat
                        Redhat
                     OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.