Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 42: civetweb Major Buffer Overflow Threat 2025-7ddaa1e0bd

fedora
Calendar Grey September 12, 2025
Dist Fedora Esm H88
A critical buffer overflow vulnerability has been found in the civetweb package for Fedora 42. Update now to secure your system against exploitation
civetweb 1.16, rhbz#2391892

Summary

Civetweb is an easy to use, powerful, C (C/C++) embeddable web server

with optional CGI, SSL and Lua support.

CivetWeb can be used by developers as a library, to add web server

functionality to an existing application. It can also be used by end

users as a stand-alone web server running on a Windows or Linux PC.

It is available as single executable, no installation is required.

Update Information:

civetweb 1.16, rhbz#2391892

Change Log

* Wed Sep 3 2025 Kaleb S. KEITHLEY - 1.16-9 - civetweb 1.16, rhbz#2391892 * Wed Jul 23 2025 Fedora Release Engineering - 1.16-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Wed Jul 16 2025 Kaleb S. KEITHLEY - 1.16-7 - civetweb 1.16, rhbz#2380496

References


[ 1 ] Bug #2391892 - CVE-2025-55763 civetweb: CivetWeb buffer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2391892

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7ddaa1e0bd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: civetweb
Product: Fedora 42
Version: 1.16
Release: 9.fc42
Summary: Embedded C/C++ web server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here