OSV-2025-564

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/https://github.com/ntop/nDPI.git/OSV-2025-564.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-564
Published
2025-07-21T00:03:40.000875Z
Modified
2025-07-21T00:03:40.001170Z
Summary
Heap-buffer-overflow in ndpi_match_host_subprotocol
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=432880859

Crash type: Heap-buffer-overflow READ 2
Crash state:
ndpi_match_host_subprotocol
check_content_type_and_change_protocol
process_request
References

Affected packages

OSS-Fuzz / ndpi

Package

Name
ndpi
Purl
pkg:generic/ndpi

Affected ranges

Type
GIT
Repo
https://github.com/ntop/nDPI.git
Events

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

{
    "fixed_range": "6785ae3825399519de8bc95a3c58dabc1b91bda8:ae48c8df7a7b01e67838572621b758e4b2d966ec",
    "introduced_range": "5f312c0cd6621fe6aaaf97a30937ce1a72833953:6785ae3825399519de8bc95a3c58dabc1b91bda8"
}