CVE-2025-62689: Null Pointer Dereference
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GNU libmicrohttpdto a version that resolves this vulnerability.Patch ff13abc
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62689?
CVE-2025-62689 has a severity rating that indicates it can lead to a denial-of-service condition.
How do I fix CVE-2025-62689?
To fix CVE-2025-62689, upgrade to GNU libmicrohttpd version 1.0.3 or later.
What are the consequences of exploiting CVE-2025-62689?
Exploiting CVE-2025-62689 can lead to a denial-of-service attack that disrupts the availability of the affected service.
Which versions of libmicrohttpd are affected by CVE-2025-62689?
CVE-2025-62689 affects GNU libmicrohttpd version 1.0.2 and earlier.
Is CVE-2025-62689 a remote exploit vulnerability?
Yes, CVE-2025-62689 can be exploited remotely by sending specially crafted packets.