MGASA-2018-0250
Dashboard / Vulnerabilities / MGASA-2018-0250
Summary: Updated miniupnpc packages fix security vulnerability
Details: It was discovered that miniupnpc contained a heap buffer overflow in parseelt (minixml.c - no CVE assigned). It was discovered that miniupnpc also contained a memory corruption (invalid read, SIGSEGV) in NameValueParserEndElt (upnpreplyparse.c) while handling two consecutive malformed SOAP requests (CVE-2017-1000494).
References: https://advisories.mageia.org/MGASA-2018-0250.html, https://bugs.mageia.org/show_bug.cgi?id=22560, https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-1000494.html, https://github.com/miniupnp/miniupnp/issues/268
Affected packages
Package
Name: miniupnpc
Purl: pkg:rpm/mageia/miniupnpc?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
