Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-65502

Опубликовано: 24 нояб. 2025
Источник: debian

Описание

Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongoosenot-affectedpackage
swupdatefixed2025.12+dfsg-1package
swupdateno-dsatrixiepackage
swupdateno-dsabookwormpackage
swupdatepostponedbullseyepackage

Примечания

  • https://github.com/cesanta/mongoose/issues/3306

  • https://github.com/cesanta/mongoose/commit/64abf061bf018fd78f31c200a57a3fb04f9f3ef2 (7.20)

Связанные уязвимости

CVSS3: 4.3
ubuntu
9 месяцев назад

Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.

CVSS3: 4.3
nvd
9 месяцев назад

Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.

CVSS3: 4.3
github
9 месяцев назад

Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL.