{"id":"DEBIAN-CVE-2025-67125","details":"A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docopt_private.h) when merging occurrence counters (e.g., default LONG_MAX + first user \"-v/--verbose\") can cause counter wrap (negative/unbounded semantics) and lead to logic/policy bypass in applications that rely on occurrence-based limits, rate-gating, or safety toggles. In hardened builds (e.g., UBSan or -ftrapv), the overflow may also result in process abort (DoS).","modified":"2026-09-01T20:05:56.879449542Z","published":"2026-01-23T16:15:52.347Z","upstream":["CVE-2025-67125"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-67125"}],"affected":[{"package":{"name":"docopt.cpp","ecosystem":"Debian:12","purl":"pkg:deb/debian/docopt.cpp?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.2-2.3","0.6.2-2.4","0.6.3-1","0.6.3-2","0.6.3-3","0.6.3-4","0.6.3-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-67125.json"}},{"package":{"name":"docopt.cpp","ecosystem":"Debian:13","purl":"pkg:deb/debian/docopt.cpp?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.3-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-67125.json"}},{"package":{"name":"docopt.cpp","ecosystem":"Debian:14","purl":"pkg:deb/debian/docopt.cpp?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.3-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-67125.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"}]}