Back Linuxsecurity openSUSE Leap 16.0 Critical Buffer Overflow in libmicrohttpd CVE-2025
This update for libmicrohttpd fixes the following issues: - CVE-2025-62689: Fixed heap-based buffer overflow through a specially crafted packet (bsc#1253178) - CVE-2025-59777: Fixed NULL pointer dereference through a specially crafted packet (bsc#1253177) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-130=1
- openSUSE Leap 16.0: libmicrohttpd-devel-1.0.1-160000.3.1 libmicrohttpd12-1.0.1-160000.3.1
libmicrohttpd-devel-1.0.1-160000.3.1
libmicrohttpd12-1.0.1-160000.3.1
* bsc#1253177 * bsc#1253178 References: * *
*
*
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
