PT-2019-12889 · Miniupnp+1 · Miniupnpd+1
Publicado
2019-10-17
·
Atualizado
2019-10-22
·
CVE-2019-12611
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Bitdefender BOX firmware versions prior to 2.1.37.37-34
Description
An issue affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or trigger a device reboot.
Recommendations
For versions prior to 2.1.37.37-34, update to version 2.1.37.37-34 or later to resolve the issue. As a temporary workaround, consider restricting access to the miniupnpd component to minimize the risk of exploitation.
Correção
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bitdefender Box
Miniupnpd