A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.
References
Link | Resource |
---|---|
https://www.vdoo.com/blog/security-issues-discovered-in-miniupnp | Exploit Patch Third Party Advisory |
https://github.com/miniupnp/miniupnp/commit/cb8a02af7a5677cf608e86d57ab04241cf34e24f | Patch |
https://lists.debian.org/debian-lts-announce/2019/05/msg00045.html | Mailing List Third Party Advisory |
https://usn.ubuntu.com/4542-1/ |
Information
Published : 2019-05-15 16:29
Updated : 2020-09-28 13:15
NVD link : CVE-2019-12111
Mitre link : CVE-2019-12111
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
debian
- debian_linux
miniupnp_project
- miniupnpd