UbuntuUpdates.org

Package "libcivetweb1"

Name: libcivetweb1

Description:

embeddable web server with optional CGI, SSL and Lua support (lib)

Latest version: 1.16+dfsg-1ubuntu0.1
Release: noble (24.04)
Level: security
Repository: universe
Head package: civetweb
Homepage: https://github.com/civetweb/civetweb/

Links


Download "libcivetweb1"


Other versions of "libcivetweb1" in Noble

Repository Area Version
base universe 1.16+dfsg-1build1
updates universe 1.16+dfsg-1ubuntu0.1

Changelog

Version: 1.16+dfsg-1ubuntu0.1 2026-09-14 01:07:21 UTC

civetweb (1.16+dfsg-1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Arbitrary Code Execution
    - debian/patches/CVE-2025-55763.patch: Fix heap overflow in
      directory URI slash redirection
    - CVE-2025-55763
  * SECURITY UPDATE: Denial of Service
    - debian/patches/CVE-2025-9648.patch: Make parsing of URL encoded
      forms more robust
    - CVE-2025-9648

 -- Bruce Cable Wed, 02 Sep 2026 11:12:25 +1000

CVE-2025-55763 Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP
CVE-2025-9648 A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By



About   -   Send Feedback to @ubuntu_updates