Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0805-1

Опубликовано: 13 июн. 2020
Источник: suse-cvrf

Описание

Security update for libupnp

This update for libupnp fixes the following issues:

  • CVE-2020-13848: A NULL ptr denial of service via crafted SSDP message was fixed (boo#1172625)

Список пакетов

openSUSE Leap 15.1
libupnp-devel-1.6.25-lp151.3.3.1
libupnp6-1.6.25-lp151.3.3.1
libupnp6-32bit-1.6.25-lp151.3.3.1

Описание

Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.


Затронутые продукты
openSUSE Leap 15.1:libupnp-devel-1.6.25-lp151.3.3.1
openSUSE Leap 15.1:libupnp6-1.6.25-lp151.3.3.1
openSUSE Leap 15.1:libupnp6-32bit-1.6.25-lp151.3.3.1

Ссылки