CVE-2015-6031
02.11.2015, 19:59
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.Enginsight
Vendor | Product | Version |
---|---|---|
miniupnp_project | miniupnpc | 𝑥 ≤ 1.9 |
miniupnp_project | miniupnpc | 1.9:2014-02-03 |
miniupnp_project | miniupnpc | 1.9:2014-02-05 |
miniupnp_project | miniupnpc | 1.9:2014-05-15 |
miniupnp_project | miniupnpc | 1.9:2014-06-10 |
miniupnp_project | miniupnpc | 1.9:2014-07-01 |
miniupnp_project | miniupnpc | 1.9:2014-09-06 |
miniupnp_project | miniupnpc | 1.9:2014-09-11 |
miniupnp_project | miniupnpc | 1.9:2014-11-05 |
miniupnp_project | miniupnpc | 1.9:2014-11-13 |
miniupnp_project | miniupnpc | 1.9:2014-11-17 |
miniupnp_project | miniupnpc | 1.9:2015-04-27 |
miniupnp_project | miniupnpc | 1.9:2015-04-30 |
miniupnp_project | miniupnpc | 1.9:2015-05-22 |
miniupnp_project | miniupnpc | 1.9:2015-06-16 |
miniupnp_project | miniupnpc | 1.9:2015-07-15 |
miniupnp_project | miniupnpc | 1.9:2015-07-22 |
miniupnp_project | miniupnpc | 1.9:2015-07-23 |
miniupnp_project | miniupnpc | 1.9:2015-08-16 |
miniupnp_project | miniupnpc | 1.9:2015-08-27 |
miniupnp_project | miniupnpc | 1.9:2015-08-28 |
miniupnp_project | miniupnpc | 1.9:2015-09-15 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.04 |
opensuse | leap | 42.1 |
opensuse | opensuse | 13.1 |
opensuse | opensuse | 13.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References