gupnp could be made to expose sensitive information or perform network
attacks if it received specially crafted network traffic.
Software Description:
- gupnp: framework for creating UPnP devices and control points
Details:
It was discovered that GUPnP incorrectly handled certain subscription
requests. A remote attacker could possibly use this issue to exfiltrate
data or use GUPnP to perform DDoS attacks.
The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libgupnp-1.2-0 1.2.3-0ubuntu0.20.04.1 After a standard system update you need to reboot your computer to make all the necessary changes.
https://ubuntu.com/security/notices/USN-4494-1
CVE-2020-12695
Get the latest Linux and open source security news straight to your inbox.