Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-12695

Опубликовано: 08 июн. 2020
Источник: debian
EPSS Низкий

Описание

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wpafixed2:2.9.0-16package
gupnpfixed1.2.3-1package
gupnpfixed1.0.5-0+deb10u1busterpackage
minidlnafixed1.2.1+dfsg-3package
pupnpnot-affectedpackage
pupnp-1.8removedpackage
pupnp-1.8ignoredbookwormpackage
pupnp-1.8no-dsabullseyepackage
pupnp-1.8no-dsabusterpackage
libupnpremovedpackage
libupnpno-dsastretchpackage

Примечания

  • https://w1.fi/security/2020-1/upnp-subscribe-misbehavior-wps-ap.txt

  • https://w1.fi/security/2020-1/0001-WPS-UPnP-Do-not-allow-event-subscriptions-with-URLs-.patch

  • https://w1.fi/security/2020-1/0002-WPS-UPnP-Fix-event-message-generation-using-a-long-U.patch

  • https://w1.fi/security/2020-1/0003-WPS-UPnP-Handle-HTTP-initiation-failures-for-events-.patch

  • https://sourceforge.net/p/minidlna/git/ci/06ee114731612462eb1eb1266f0431ccf59269d2 (v1_3_0)

  • https://github.com/pupnp/pupnp/commit/5f76bf2858dd601bd985bf37a1db9f262c0ff7bf (release-1.14.0)

  • https://github.com/pupnp/pupnp/commit/7b3f0f5f497f9f493c82307af495b87fa9ebdacb (release-1.14.0)

EPSS

Процентиль: 86%
0.0293
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

CVSS3: 7.5
redhat
около 5 лет назад

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

CVSS3: 7.5
nvd
около 5 лет назад

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

rocky
около 4 лет назад

Moderate: gssdp and gupnp security update

CVSS3: 7.5
github
около 3 лет назад

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

EPSS

Процентиль: 86%
0.0293
Низкий