UbuntuUpdates.org

Package "civetweb"

Name: civetweb

Description:

embeddable web server with optional CGI, SSL and Lua support

Latest version: 1.16+dfsg-1ubuntu0.1
Release: noble (24.04)
Level: updates
Repository: universe
Homepage: https://github.com/civetweb/civetweb/

Links


Download "civetweb"


Other versions of "civetweb" in Noble

Repository Area Version
base universe 1.16+dfsg-1build1
security universe 1.16+dfsg-1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.16+dfsg-1ubuntu0.1 2026-09-14 03:07:33 UTC

civetweb (1.16+dfsg-1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Arbitrary Code Execution
    - debian/patches/CVE-2025-55763.patch: Fix heap overflow in
      directory URI slash redirection
    - CVE-2025-55763
  * SECURITY UPDATE: Denial of Service
    - debian/patches/CVE-2025-9648.patch: Make parsing of URL encoded
      forms more robust
    - CVE-2025-9648

 -- Bruce Cable Wed, 02 Sep 2026 11:12:25 +1000

CVE-2025-55763 Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP
CVE-2025-9648 A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By



About   -   Send Feedback to @ubuntu_updates