Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-33516

Опубликовано: 24 мая 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8
CVSS3: 8.1

Описание

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

released

1.2.4-1ubuntu1
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

DNE

esm-infra/focal

released

1.2.3-0ubuntu0.20.04.2
focal

released

1.2.3-0ubuntu0.20.04.2
groovy

released

1.2.4-1ubuntu0.20.10.1
hirsute

released

1.2.4-1ubuntu0.21.04.1

Показывать по

5.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
redhat
около 5 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

CVSS3: 8.1
nvd
около 5 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.

CVSS3: 8.1
debian
около 5 лет назад

An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x befo ...

suse-cvrf
около 5 лет назад

Security update for gupnp

suse-cvrf
около 5 лет назад

Security update for gupnp

5.8 Medium

CVSS2

8.1 High

CVSS3