SB2025091927 - NULL pointer dereference in poco
Published: September 19, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-6375)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the function MultipartInputStream of the file Net/src/MultipartReader.cpp. A local user can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://github.com/pocoproject/poco/commit/6f2f85913c191ab9ddfb8fae781f5d66afccf3bf
- https://github.com/pocoproject/poco/issues/4915
- https://github.com/pocoproject/poco/releases/tag/poco-1.14.2-release
- https://github.com/user-attachments/files/19524599/poco_crash.txt
- https://vuldb.com/?ctiid.313370
- https://vuldb.com/?id.313370
- https://vuldb.com/?submit.597446