Logo
vulnerabilityCVE-2025-55763
Name
CVE-2025-55763
Source
NVD ( link)Debian ( link)
Description
Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
civetweb
Patched

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.16
Patched
buildroot
master
1.16
Patched
yocto
kirkstone
1.12+gitX
Not Affected
yocto
master
1.16+git
Not Affected

Resolved with patches#


civetweb (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix heap overflow in directory URI slash redirection
krispybyte <krispybyte@proton.me>
CVE-2025-55763

civetweb (buildroot:master)

#
Title
Author
Resolve
1
Fix heap overflow in directory URI slash redirection
krispybyte <krispybyte@proton.me>
CVE-2025-55763

civetweb (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix heap overflow in directory URI slash redirection
krispybyte <krispybyte@proton.me>
CVE-2025-55763