Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2020-0270 Moderate: libupnp Remote Denial of Service Threat

mageia
Calendar Grey July 4, 2020
Dist Mageia Esm H88
Recent libupnp updates address a critical security vulnerability in Mageia. Find out more about the potential dangers associated with remote exploits.
The updated packages fix a security vulnerability: Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SS...

Summary

The updated packages fix a security vulnerability:
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c. (CVE-2020-13848)

References

- https://bugs.mageia.org/show_bug.cgi?id=26752

- https://lists.debian.org/debian-lts-announce/2020/06/msg00006.html

- https://www.cve.org/CVERecord?id=CVE-2020-13848

Resolution

SRPMS

- 7/core/libupnp-1.8.4-3.1.mga7

Publication date: 04 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0270.html
Type: security
CVE: CVE-2020-13848

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here