CVE-2014-3985Project Miniupnp vulnerability

6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
1.9%
top 16.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 13

Description

The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/miniupnpc< miniupnpc 1.6-4 (bookworm)
NVDopensuse/opensuse12.3, 13.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jwgg-6gv4-m9cx: The getHTTPResponse function in miniwget2022-05-13
OSV
CVE-2014-3985: The getHTTPResponse function in miniwget2014-09-11

📋Vendor Advisories

2
Ubuntu
MiniUPnPc vulnerability2014-07-16
Debian
CVE-2014-3985: miniupnpc - The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attacke...2014

💬Community

1
Bugzilla
CVE-2014-3985 miniupnpc buffer overrun - network facing DoS crash2014-04-09