{"id":"CVE-2025-52937","summary":"Vulnerability in PointCloudLibrary PCL","details":"Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C.\n\nThis vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib (WITH_SYSTEM_ZLIB=FALSE).","modified":"2026-08-12T15:16:39.125481Z","published":"2025-06-23T09:26:12.727Z","database_specific":{"cna_assigner":"GovTech CSG","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52937.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52937.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52937"},{"type":"FIX","url":"https://github.com/PointCloudLibrary/pcl/commit/2f9dc390c6769fbd821fafa0e16f4707ed7c5d79"},{"type":"FIX","url":"https://github.com/PointCloudLibrary/pcl/pull/6275"},{"type":"PACKAGE","url":"https://github.com/PointCloudLibrary/pcl"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pointcloudlibrary/pcl","events":[{"introduced":"0"},{"fixed":"2f9dc390c6769fbd821fafa0e16f4707ed7c5d79"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.14.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["pcl-1.15.0","pcl-1.15.0-rc1","pcl-1.14.1","pcl-1.14.1-rc1","pcl-1.14.0","pcl-1.14.0-rc1","pcl-1.13.1","pcl-1.13.1-rc1","pcl-1.13.0-rc1","pcl-1.13.0","pcl-1.12.1","pcl-1.12.0-rc1","pcl-1.12.0","pcl-1.11.1","pcl-1.11.1-rc2","pcl-1.11.1-rc1","pcl-1.11.0","pcl-1.10.1","pcl-1.10.0","pcl-1.9.1","pcl-1.9.0","pcl-1.8.0","pcl-1.8.0rc2","pcl-1.8.0rc1","pcl-1.0-ros"],"database_specific":{"vanir_signatures":[{"source":"https://github.com/pointcloudlibrary/pcl/commit/2f9dc390c6769fbd821fafa0e16f4707ed7c5d79","target":{"file":"surface/src/3rdparty/opennurbs/crc32.c"},"deprecated":false,"digest":{"line_hashes":["195981212041908091742204017907408717117","153995273716650374983599690365599552288","338055270158328592056354744226160722636","308291083902588863513051812526272651423","294350683247765337501808918320149236938","107303620715830101356486921414690028808","56257635472176494025514288891627516122","48419906790453504580546155601585011871","129288830573974287994851663631918110070","309613971747137665366059309652626476656","59808224210313279059403352897595966020"],"threshold":0.9},"id":"CVE-2025-52937-cc937a2b","signature_type":"Line","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52937.json","vanir_signatures_modified":"2026-08-12T15:16:39Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/S:N/AU:N/R:A/V:D/RE:M/U:Green"}]}