poco MultipartReader.cpp MultipartInputStream null pointer dereference

CVE Details

Basic Information

Title poco MultipartReader.cpp MultipartInputStream null pointer dereference
Type cve
Published 2025-06-21T00:31:06.881Z
Last Seen

Product Information

Vendor n/a
Product poco
Version 1.14.0

CVSS Information

Base Score 4.8 (MEDIUM)
Attack Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A null pointer dereference vulnerability in the MultipartReader.cpp of POCO can cause a denial of service. This issue affects versions up to 1.14.1 and can be fixed by upgrading to version 1.14.2.
AI Severity Medium
Vendor POCO Project Community
Product poco
Affected Version 1.14.0, 1.14.1

Affected Products

  • n/a poco 1.14.0
  • n/a poco 1.14.1

Additional Information

CVE List
CWE List CWE-476, CWE-404
Bulletin Family

Description

A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is the function MultipartInputStream of the file Net/src/MultipartReader.cpp. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.14.2 is able to address this issue. The patch is identified as 6f2f85913c191ab9ddfb8fae781f5d66afccf3bf. It is recommended to upgrade the affected component.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.