NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | libmicrohttpd: GNU libmicrohttpd null pointer dereference | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu libmicrohttpd |
|
| Vendors & Products |
Gnu
Gnu libmicrohttpd |
Mon, 10 Nov 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition. | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-11-10T04:10:57.970Z
Updated: 2025-11-10T04:10:57.970Z
Reserved: 2025-11-03T23:35:49.815Z
Link: CVE-2025-62689
No data.
Status : Awaiting Analysis
Published: 2025-11-10T05:15:49.087
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-62689