Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8863

Опубликовано: 07 мар. 2017
Источник: debian
EPSS Средний

Описание

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libupnpfixed1:1.6.19+git20160116-1.2package
libupnp4removedpackage

Примечания

  • https://sourceforge.net/p/pupnp/bugs/133/

  • Patch: https://sourceforge.net/p/pupnp/bugs/_discuss/thread/f2781a77/d8a2/attachment/0001-Fix-out-of-bound-access-in-create_url_list-CVE-2016-.patch

EPSS

Процентиль: 96%
0.24433
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.

CVSS3: 9.8
nvd
почти 9 лет назад

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.

CVSS3: 9.8
github
больше 3 лет назад

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.

suse-cvrf
больше 8 лет назад

Security update for libupnp

EPSS

Процентиль: 96%
0.24433
Средний