Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-8798Improper Restriction of Operations within the Bounds of a Memory Buffer in Miniupnpc

Severity
9.8CRITICALNVD
EPSS
23.5%
top 4.01%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 11
Latest updateMay 13

Description

Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

debiandebian/miniupnpc< miniupnpc 1.9.20140610-3 (bookworm)
NVDminiupnp_project/miniupnpd6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-3wfp-98cg-vgm9: Integer signedness error in MiniUPnP MiniUPnPc v12022-05-13
OSV
CVE-2017-8798: Integer signedness error in MiniUPnP MiniUPnPc v12017-05-11

💥Exploits & PoCs

1
Exploit-DB
MiniUPnP MiniUPnPc < 2.0 - Remote Denial of Service2017-05-11

📋Vendor Advisories

3
Ubuntu
MiniUPnP vulnerability2017-05-24
Ubuntu
MiniUPnP vulnerability2017-05-24
Debian
CVE-2017-8798: miniupnpc - Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows...2017

💬Community

4
HackerOne
CVE-2017-8798 - miniupnp getHTTPResponse chunked encoding integer signedness error2019-11-12
Bugzilla
CVE-2017-8798 miniupnpc: Integer signedness error2017-05-11
Bugzilla
CVE-2017-8798 miniupnpc: Integer signedness error [epel-7]2017-05-11
Bugzilla
CVE-2017-8798 miniupnpc: Integer signedness error [fedora-all]2017-05-11