CVE-2017-1000494Improper Restriction of Operations within the Bounds of a Memory Buffer in Project Miniupnpd

Severity
7.8HIGHNVD
EPSS
0.1%
top 76.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 3
Latest updateMay 14

Description

Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/miniupnpd< miniupnpc 2.0.20171212-3 (bookworm)
Debianminiupnp_project/miniupnpd< 2.0.20171212-1+3
debiandebian/miniupnpc< miniupnpc 2.0.20171212-3 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cmwg-g372-6738: Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse2022-05-14
OSV
CVE-2017-1000494: Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse2018-01-03

📋Vendor Advisories

2
Ubuntu
MiniUPnP vulnerabilities2018-02-07
Debian
CVE-2017-1000494: miniupnpc - Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplypa...2017

🕵️Threat Intelligence

4
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities2019-03-06
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities2019-03-06
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities2019-03-06
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities2019-03-06

💬Community

3
Bugzilla
CVE-2017-1000494 miniupnpc: Multiple vulnerabilities can allow a remote attacker to cause a denial of service or potentially execute code2018-01-09
Bugzilla
CVE-2017-1000494 miniupnpc: Multiple vulnerabilities can allow a remote attacker to cause a denial of service or potentially execute code [fedora-all]2018-01-09
Bugzilla
CVE-2017-1000494 miniupnpc: Multiple vulnerabilities can allow a remote attacker to cause a denial of service or potentially execute code [epel-all]2018-01-09