CVE-2012-5958: Buffer Overflow
Stack-based buffer overflow in the uniqueservicename function in ssdp/ssdpserver.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a UDP packet with a crafted string that is not properly handled after a certain pointer subtraction.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5958?
CVE-2012-5958 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2012-5958?
To mitigate CVE-2012-5958, you should upgrade to libupnp version 1.6.18 or later.
What are the potential impacts of CVE-2012-5958?
The exploitation of CVE-2012-5958 can lead to complete system compromise and unauthorized access to sensitive data.
Which versions of libupnp are affected by CVE-2012-5958?
Versions of libupnp prior to 1.6.18, including all versions from 1.4.0 through 1.6.17, are affected by CVE-2012-5958.
Who can be affected by CVE-2012-5958?
Any system running an affected version of libupnp that exposes UDP services could potentially be targeted by attackers exploiting CVE-2012-5958.