Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade miniupnpc | Nov 9, 2015 | Oct 25, 2015 |
| Freebsd | — | Upgrade miniupnpc | Dec 10, 2025 | Oct 14, 2015 |
| Gentoo Linux | — | Upgrade net-libs/miniupnpc. | Jan 8, 2018 | Nov 2, 2015 |
| Suse | — | Upgrade python-miniupnpcUpgrade libminiupnpc-develUpgrade libminiupnpc10Upgrade libminiupnpc10-debuginfo-32bitUpgrade python-miniupnpc-debuginfoUpgrade miniupnpcUpgrade libminiupnpc10-debuginfoUpgrade miniupnpc-debuginfoUpgrade libminiupnpc10-32bit | Dec 18, 2015 | Nov 2, 2015 |
| Ubuntu | — | Upgrade libminiupnpc8Upgrade libminiupnpc10 | Nov 8, 2024 | Nov 2, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub