Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-62689

Опубликовано: 10 нояб. 2025
Источник: redhat
CVSS3: 5.3

Описание

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.

A null pointer dereference vector has been discovered in GNU libmicrohttpd. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) in the application using libmicrohttpd.

Отчет

The availability impact of this flaw is limited to applications using libmicrohttpd. Red Hat host operating systems are not at risk.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libmicrohttpdWill not fix
Red Hat Enterprise Linux 6libmicrohttpdOut of support scope
Red Hat Enterprise Linux 7libmicrohttpdOut of support scope
Red Hat Enterprise Linux 8libmicrohttpdNot affected
Red Hat Enterprise Linux 9libmicrohttpdWill not fix
Red Hat OpenShift Container Platform 4rhcosWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2413716libmicrohttpd: GNU libmicrohttpd null pointer dereference

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.

CVSS3: 7.5
nvd
5 месяцев назад

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.

msrc
5 месяцев назад

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.

CVSS3: 7.5
debian
5 месяцев назад

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1. ...

CVSS3: 7.5
github
5 месяцев назад

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.

5.3 Medium

CVSS3