Описание
Security update for libupnp
This update for libupnp fixes the following issues:
- CVE-2020-13848: A NULL ptr denial of service via crafted SSDP message was fixed (boo#1172625)
Список пакетов
openSUSE Leap 15.1
libupnp-devel-1.6.25-lp151.3.3.1
libupnp6-1.6.25-lp151.3.3.1
libupnp6-32bit-1.6.25-lp151.3.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0805-1
- SUSE Security Ratings
- SUSE Bug 1172625
- SUSE CVE CVE-2020-13848 page
Описание
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.
Затронутые продукты
openSUSE Leap 15.1:libupnp-devel-1.6.25-lp151.3.3.1
openSUSE Leap 15.1:libupnp6-1.6.25-lp151.3.3.1
openSUSE Leap 15.1:libupnp6-32bit-1.6.25-lp151.3.3.1
Ссылки
- CVE-2020-13848
- SUSE Bug 1172625