GNU libmicrohttpd
cpe:2.3:a:gnu:libmicrohttpd:*:*:*:*:*:*:*
- <= 1.0.2
A NULL pointer dereference vulnerability has been identified in GNU Libmicrohttpd versions through 1.0.2. This vulnerability, present in the experimental WebSocket support library 'libmicrohttpd_ws.so', can be exploited by sending a specially crafted packet, potentially leading to a denial-of-service condition.
Exploitation of this vulnerability can cause a denial-of-service condition, causing the application to crash or become unresponsive.
Users are advised to stop using 'libmicrohttpd_ws.so', as it is an experimental implementation. The vulnerability has been fixed in the official GNU Libmicrohttpd Git repository after the v1.0.2 tag.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.