CVE-2015-6031
02.11.2015, 19:59
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.Enginsight
| Vendor | Product | Version |
|---|---|---|
| miniupnp_project | miniupnpc | 𝑥 ≤ 1.9 |
| miniupnp_project | miniupnpc | 1.9:2014-02-03 |
| miniupnp_project | miniupnpc | 1.9:2014-02-05 |
| miniupnp_project | miniupnpc | 1.9:2014-05-15 |
| miniupnp_project | miniupnpc | 1.9:2014-06-10 |
| miniupnp_project | miniupnpc | 1.9:2014-07-01 |
| miniupnp_project | miniupnpc | 1.9:2014-09-06 |
| miniupnp_project | miniupnpc | 1.9:2014-09-11 |
| miniupnp_project | miniupnpc | 1.9:2014-11-05 |
| miniupnp_project | miniupnpc | 1.9:2014-11-13 |
| miniupnp_project | miniupnpc | 1.9:2014-11-17 |
| miniupnp_project | miniupnpc | 1.9:2015-04-27 |
| miniupnp_project | miniupnpc | 1.9:2015-04-30 |
| miniupnp_project | miniupnpc | 1.9:2015-05-22 |
| miniupnp_project | miniupnpc | 1.9:2015-06-16 |
| miniupnp_project | miniupnpc | 1.9:2015-07-15 |
| miniupnp_project | miniupnpc | 1.9:2015-07-22 |
| miniupnp_project | miniupnpc | 1.9:2015-07-23 |
| miniupnp_project | miniupnpc | 1.9:2015-08-16 |
| miniupnp_project | miniupnpc | 1.9:2015-08-27 |
| miniupnp_project | miniupnpc | 1.9:2015-08-28 |
| miniupnp_project | miniupnpc | 1.9:2015-09-15 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.04 |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.1 |
| opensuse | opensuse | 13.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References