Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-2417

Опубликовано: 15 июн. 2021
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2021-2417: gupnp security update (IMPORTANT)

[1.0.2-6]

  • gupnp-1.0.3-3
  • Fix DNS rebind issue
  • Resolves: #1964706

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

gupnp

1.0.2-6.el7_9

gupnp-devel

1.0.2-6.el7_9

gupnp-docs

1.0.2-6.el7_9

Oracle Linux x86_64

gupnp

1.0.2-6.el7_9

gupnp-devel

1.0.2-6.el7_9

gupnp-docs

1.0.2-6.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 4 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

CVSS3: 8.3
redhat
около 4 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

CVSS3: 8.1
nvd
около 4 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

CVSS3: 8.1
debian
около 4 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x befo ...

suse-cvrf
почти 4 года назад

Security update for gupnp