Skip to content

Latest commit

 

History

History
executable file
·
47 lines (29 loc) · 1.03 KB

miniupnpd-getoutboundpinholetimeout-null-pointer-dereference-xray-148212.md

File metadata and controls

executable file
·
47 lines (29 loc) · 1.03 KB
description title date_published last_updated xray_id vul_id cvss severity discovered_by type
CVE-2019-12109 High severity. Denial Of Service in MiniUPnPd due to a NULL pointer dereference in upnpsoap.c for rem_port
MiniUPnPd GetOutboundPinholeTimeout NULL pointer dereference
2019-02-06
2019-02-06
XRAY-148212
CVE-2019-12109
7.5
high
Ben Barnea
vulnerability

Summary

Denial Of Service in MiniUPnPd due to a NULL pointer dereference in upnpsoap.c for rem_port

Component

MiniUPnP

Affected versions

MiniUPnP (,2.1], fixed in 2.2.0

Description

It was discovered that MiniUPnPd incorrectly handled unpopulated user XML input. An attacker could possibly use this issue to cause MiniUPnPd to crash, resulting in a denial of service.

PoC

No PoC is supplied for this issue

Vulnerability Mitigations

No vulnerability mitigations are supplied for this issue

References

NVD

NVD