=========================================================================Ubuntu Security Notice USN-4494-1
September 15, 2020

gupnp vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

gupnp could be made to expose sensitive information or perform network
attacks if it received specially crafted network traffic.

Software Description:
- gupnp: framework for creating UPnP devices and control points

Details:

It was discovered that GUPnP incorrectly handled certain subscription
requests. A remote attacker could possibly use this issue to exfiltrate
data or use GUPnP to perform DDoS attacks.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  libgupnp-1.2-0                  1.2.3-0ubuntu0.20.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4494-1
  CVE-2020-12695

Package Information:
  https://launchpad.net/ubuntu/+source/gupnp/1.2.3-0ubuntu0.20.04.1

Ubuntu 4494-1: GUPnP vulnerability

September 15, 2020
gupnp could be made to expose sensitive information or perform network attacks if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libgupnp-1.2-0 1.2.3-0ubuntu0.20.04.1 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4494-1

CVE-2020-12695

Severity
September 15, 2020

Package Information

https://launchpad.net/ubuntu/+source/gupnp/1.2.3-0ubuntu0.20.04.1

Related News