CVE-2015-6031
Published: 16 October 2015
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
Priority
Status
Package | Release | Status |
---|---|---|
miniupnpc Launchpad, Ubuntu, Debian |
precise |
Released
(1.6-3ubuntu1.2)
|
trusty |
Released
(1.6-3ubuntu2.14.04.2)
|
|
upstream |
Needs triage
|
|
vivid |
Released
(1.9.20140610-2ubuntu1.1)
|
|
wily |
Released
(1.9.20140610-2ubuntu2)
|
|
Patches: upstream: https://github.com/miniupnp/miniupnp/commit/79cca974a4c2ab1199786732a67ff6d898051b78 |