PT-2015-7119 · Miniupnp+2 · Miniupnpc+2

Aleksandar Nikolic

·

Publicado

2015-10-16

·

Atualizado

2025-03-10

·

CVE-2015-6031

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MiniUPnP client (aka MiniUPnPc) versions prior to 1.9.20150917
Description The issue is related to a buffer overflow in the IGDstartelt function in igd desc parse.c. This allows remote UPNP servers to potentially cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
Recommendations For versions prior to 1.9.20150917, update to version 1.9.20150917 or later to resolve the issue. As a temporary workaround, consider restricting access to the MiniUPnP client to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-3253
CVE-2015-6031
DSA-3379-1
MGASA-2015-0416
USN-2780-1
USN-2780-2

Produtos afetados

Alt Linux
Miniupnpc
Ubuntu