libupnp Multiple Buffer Overflow Vulnerabilities
BID:57602
Info
libupnp Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 57602 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-5958 CVE-2012-5959 CVE-2012-5960 CVE-2012-5961 CVE-2012-5962 CVE-2012-5963 CVE-2012-5964 CVE-2012-5965 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2013 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | HD Moore of Rapid7 |
| Vulnerable: |
Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
libupnp Multiple Buffer Overflow Vulnerabilities
libupnp is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary code in the context of the device that uses the affected library. Failed exploit attempts will likely crash the application.
libupnp versions prior to 1.6.18 are affected.
libupnp is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit these issues to execute arbitrary code in the context of the device that uses the affected library. Failed exploit attempts will likely crash the application.
libupnp versions prior to 1.6.18 are affected.
Exploit / POC
libupnp Multiple Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example request is available:
M-SEARCH * HTTP/1.1
Host:239.255.255.250:1900
ST:uuid:schemas:device:AAAA[â?¦]AAAA:anything
Man:"ssdp:discover"
MX:3
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example request is available:
M-SEARCH * HTTP/1.1
Host:239.255.255.250:1900
ST:uuid:schemas:device:AAAA[â?¦]AAAA:anything
Man:"ssdp:discover"
MX:3
Solution / Fix
libupnp Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
libupnp Multiple Buffer Overflow Vulnerabilities
References:
References: