Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Scott Tenaglia

#24258de 53,638
9.8CVSS total
Vulnerabilidades · 1
PT-2017-9849
9.8
2016-12-16
Libupnp · Portable Upnp Sdk · CVE-2016-8863
**Name of the Vulnerable Software and Affected Versions** Portable UPnP SDK (aka libupnp) versions prior to 1.6.21 **Description** The issue is related to a heap-based buffer overflow in the create url list function. This can be triggered by sending a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request, potentially allowing remote attackers to cause a denial of service or possibly execute arbitrary code. **Recommendations** For versions prior to 1.6.21, update to version 1.6.21 or later to resolve the issue.