NULL pointer dereference in poco - CVE-2025-6375
Published: September 19, 2025
poco
Detailed vulnerability description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the function MultipartInputStream of the file Net/src/MultipartReader.cpp. A local user can pass specially crafted data to the application and perform a denial of service (DoS) attack.
How to mitigate CVE-2025-6375
Sources
- https://github.com/pocoproject/poco/commit/6f2f85913c191ab9ddfb8fae781f5d66afccf3bf
- https://github.com/pocoproject/poco/issues/4915
- https://github.com/pocoproject/poco/releases/tag/poco-1.14.2-release
- https://github.com/user-attachments/files/19524599/poco_crash.txt
- https://vuldb.com/?ctiid.313370
- https://vuldb.com/?id.313370
- https://vuldb.com/?submit.597446