CVE-2021-33516
Summary
| CVE | CVE-2021-33516 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-24 15:15:00 UTC |
| Updated | 2021-05-28 15:41:00 UTC |
| Description | An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Issue: Server does not check value of Host header (#24) · Issues · GNOME / gupnp · GitLab | MISC | gitlab.gnome.org | |
| Security-relevant releases for GUPnP issue CVE-2021-33516 - Platform - GNOME Discourse | MISC | discourse.gnome.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159267 Oracle Enterprise Linux Security Update for gupnp (ELSA-2021-2363)
- 159279 Oracle Enterprise Linux Security Update for gupnp (ELSA-2021-2417)
- 182902 Debian Security Update for gupnp (CVE-2021-33516)
- 198389 Ubuntu Security Notification for GUPnP vulnerability (USN-4970-1)
- 239388 Red Hat Update for gupnp (RHSA-2021:2363)
- 239426 Red Hat Update for gupnp (RHSA-2021:2459)
- 239429 Red Hat Update for gupnp (RHSA-2021:2422)
- 239431 Red Hat Update for gupnp (RHSA-2021:2417)
- 352463 Amazon Linux Security Advisory for gupnp: ALAS2-2021-1673
- 377139 Alibaba Cloud Linux Security Update for gupnp (ALINUX3-SA-2021:0042)
- 377201 Alibaba Cloud Linux Security Update for gupnp (ALINUX2-SA-2021:0040)
- 671563 EulerOS Security Update for gupnp (EulerOS-SA-2022-1568)
- 671855 EulerOS Security Update for gupnp (EulerOS-SA-2022-1891)
- 672241 EulerOS Security Update for gupnp (EulerOS-SA-2022-2613)
- 750680 SUSE Enterprise Linux Security Update for gupnp (SUSE-SU-2021:2080-1)
- 750730 OpenSUSE Security Update for gupnp (openSUSE-SU-2021:0917-1)
- 750768 OpenSUSE Security Update for gupnp (openSUSE-SU-2021:2153-1)
- 940367 AlmaLinux Security Update for gupnp (ALSA-2021:2363)
- 960021 Rocky Linux Security Update for gupnp (RLSA-2021:2363)