Bug 2413716 (CVE-2025-62689) - CVE-2025-62689 libmicrohttpd: GNU libmicrohttpd null pointer dereference
Summary: CVE-2025-62689 libmicrohttpd: GNU libmicrohttpd null pointer dereference
Keywords:
Status: NEW
Alias: CVE-2025-62689
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2413883 2413885 2413887 2413889 2413891 2413893 2413894 2413895 2413896 2413897 2413898
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-11-10 05:01 UTC by OSIDB Bzimport
Modified: 2025-11-10 21:44 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-11-10 05:01:39 UTC
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.


Note You need to log in before you can comment on or make changes to this bug.