MiniUPnP 'miniwget.c' Remote Buffer Overflow Vulnerability
BID:67152
Info
MiniUPnP 'miniwget.c' Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 67152 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-3985 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2014 12:00AM |
| Updated: | Jan 23 2017 09:11AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 13.10 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 MiniUPnP Project MiniUPnP 1.8 MiniUPnP Project MiniUPnP 1.4 MiniUPnP Project MiniUPnP 1.3 MiniUPnP Project MiniUPnP 1.1 MiniUPnP Project MiniUPnP 1.0 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Gentoo Linux |
| Not Vulnerable: |
MiniUPnP Project MiniUPnP 1.9 |
Discussion
MiniUPnP 'miniwget.c' Remote Buffer Overflow Vulnerability
MiniUPnP is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Versions prior to MiniUPnP 1.9 are vulnerable.
MiniUPnP is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary-checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
Versions prior to MiniUPnP 1.9 are vulnerable.
Exploit / POC
MiniUPnP 'miniwget.c' Remote Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
MiniUPnP 'miniwget.c' Remote Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva lib64miniupnpc-devel-1.6-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64miniupnpc8-1.6-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
MiniUPnP 'miniwget.c' Remote Buffer Overflow Vulnerability
References:
References:
- Bug 1085618 - miniupnpc buffer overrun - network facing DoS crash (Red Hat Bugzilla)
- miniUPnP client Changelog (miniUPnP)
- MiniUPnP Project HomePage (MiniUPnP)
- miniwget.c: fixed potential buffer overrun (MiniUPnP)