Impact
A heap‑based buffer overflow exists in the Telnet Subnegotiation Packet handler of seladb PcapPlusPlus 25.05. The getSubCommand function can be manipulated by a crafted packet, causing a malicious buffer to overwrite adjacent heap objects. This corruption can potentially allow an attacker to alter program control flow and execute arbitrary code. The vulnerability is listed as a memory corruption weakness (CWE‑119 and CWE‑122).
Affected Systems
The flaw affects the PcapPlusPlus library version 25.05. No additional product or version data was provided, so systems using this or older iterations that include the vulnerable getSubCommand implementation are at risk.
Risk and Exploitability
The CVSS score is 6.3, indicating moderate severity. The EPSS score is not available, so the current exploitation likelihood cannot be quantified. The vulnerability is not present in the CISA KEV catalog. It can be triggered remotely via the Telnet protocol; the attack requires complex manipulation and the publicly available exploit is reported to be difficult to construct, though it may become available. Because it is a heap overflow, a successful exploit could lead to a complete compromise of the host hosting the library.
OpenCVE Enrichment