USN-4542-1
Dashboard / Vulnerabilities / USN-4542-1
USN-4542-1
Summary: miniupnpd vulnerabilities
Details: It was discovered that MiniUPnPd did not properly validate callback addresses. A remote attacker could possibly use this issue to expose sensitive information. (CVE-2019-12107) It was discovered that MiniUPnPd incorrectly handled unpopulated user XML input. An attacker could possibly use this issue to cause MiniUPnPd to crash, resulting in a denial of service. (CVE-2019-12108, CVE-2019-12109) It was discovered that MiniUPnPd incorrectly handled an empty description when port mapping. An attacker could possibly use this issue to cause MiniUPnPd to crash, resulting in a denial of service. (CVE-2019-12110) It was discovered that MiniUPnPd did not properly parse certain PCP requests. An attacker could possibly use this issue to cause MiniUPnPd to crash, resulting in a denial of service. (CVE-2019-12111)
References: https://ubuntu.com/security/notices/USN-4542-1, https://ubuntu.com/security/CVE-2019-12107, https://ubuntu.com/security/CVE-2019-12108, https://ubuntu.com/security/CVE-2019-12109, https://ubuntu.com/security/CVE-2019-12110, https://ubuntu.com/security/CVE-2019-12111
Affected packages
Package
Name: miniupnpd
Purl: pkg:deb/ubuntu/[email protected]+deb9u2build0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
