Impact
A heap‑based buffer overflow exists in the parse_by_block_type function of the LightPcapNg Parser component of PcapPlusPlus 25.05. By manipulating the captured_packet_length argument, an attacker can overflow a heap buffer, potentially compromising memory integrity or causing a program crash. The attack is described as having high complexity and difficult exploitability, yet a public exploit is available.
Affected Systems
This vulnerability affects the seladb PcapPlusPlus library, specifically version 25.05. No other versions or vendor products are listed as impacted.
Risk and Exploitability
The CVSS score is 6.3, indicating a medium severity level. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring the ability to supply manipulated packet data to the parser. The high complexity and difficult exploitability do not eliminate the risk, as a public exploit exists and could be used by adversaries with sufficient resources.
OpenCVE Enrichment