CVE-2016-6255
Summary
| CVE | CVE-2016-6255 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-07 16:59:00 UTC |
| Updated | 2017-11-03 01:29:00 UTC |
| Description | Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Matthew Garrett on Twitter: "Reported this to upstream 8 months ago without response, so: libupnp's default behaviour allows anyone to write to your filesystem" |
MISC |
twitter.com |
Third Party Advisory |
| Portable UPnP SDK / Code /
[0497e6]
/ChangeLog |
CONFIRM |
sourceforge.net |
Release Notes, Third Party Advisory |
| libupnp CVE-2016-6255 Arbitrary File Write Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| libupnp: Multiple vulnerabilities (GLSA 201701-52) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [R1] Debian MediaTomb (fork) Multiple Remote Vulnerabilities - Research Advisory | Tenable® |
MISC |
www.tenable.com |
|
| MiCasaVerde VeraLite - Remote Code Execution - Hardware remote Exploit |
EXPLOIT-DB |
www.exploit-db.com |
|
| oss-security - Re: libupnp write files via POST |
MLIST |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| oss-security - libupnp write files via POST |
MLIST |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| Don't allow unhandled POSTs to write to the filesystem by default · mjg59/pupnp-code@be0a01b · GitHub |
MISC |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-3736-1 libupnp |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710545 Gentoo Linux libupnp Multiple Vulnerabilities (GLSA 201701-52)