Vulnerability CVE-2016-6255


Published: 2017-03-07

Description:
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.

See advisories in our WLB2 database:
Topic
Author
Date
High
MiCasa VeraLite Remote Code Execution
Jacob Baines
22.10.2016

Vendor: Debian
Product: Debian linux 
Version: 8.0;
Vendor: Libupnp project
Product: Libupnp 
Version: 1.6.20;

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://www.debian.org/security/2016/dsa-3736
http://www.openwall.com/lists/oss-security/2016/07/18/13
http://www.openwall.com/lists/oss-security/2016/07/20/5
http://www.securityfocus.com/bid/92050
https://github.com/mjg59/pupnp-code/commit/be0a01bdb83395d9f3a5ea09c1308a4f1a972cbd
https://security.gentoo.org/glsa/201701-52
https://sourceforge.net/p/pupnp/code/ci/master/tree/ChangeLog
https://twitter.com/mjg59/status/755062278513319936
https://www.exploit-db.com/exploits/40589/
https://www.tenable.com/security/research/tra-2017-10

Related CVE
CVE-2016-8863
Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed...
CVE-2012-5961
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary co...
CVE-2012-5958
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbi...

Copyright 2019, cxsecurity.com

 

Back to Top