PT-2019-12889 · Miniupnp+1 · Miniupnpd+1

Publicado

2019-10-17

·

Atualizado

2019-10-22

·

CVE-2019-12611

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Bitdefender BOX firmware versions prior to 2.1.37.37-34
Description An issue affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or trigger a device reboot.
Recommendations For versions prior to 2.1.37.37-34, update to version 2.1.37.37-34 or later to resolve the issue. As a temporary workaround, consider restricting access to the miniupnpd component to minimize the risk of exploitation.

Correção

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12611

Produtos afetados

Bitdefender Box
Miniupnpd