PT-2021-2424 · Pupnp+2 · Pupnp+2

Published

2021-03-12

·

Updated

2025-06-23

·

CVE-2021-28302

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: pupnp versions prior to 1.14.5
Description: A stack overflow in the Parser parseDocument() function can cause a denial of service. The ixmlNode free() function will release a child node recursively, consuming stack space and leading to a crash. This issue is related to errors in handling XML entities.
Recommendations: For versions prior to 1.14.5, update to version 1.14.5 or later to resolve the issue. As a temporary workaround, consider disabling the Parser parseDocument() function until a patch is available.

Exploit

Fix

DoS

XML Entity Expansion

Stack Overflow

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2310
ALT-PU-2025-5462
BDU:2021-01679
CVE-2021-28302
OPENSUSE-SU-2024:11006-1

Affected Products

Alt Linux
Debian
Pupnp