CVE-2013-0229: High severity miniupnp vulnerability
Published Jan 31, 2013
·Updated
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
Affected Software
4 affected components
Miniupnp Project Miniupnpd<=1.3
Miniupnp Project Miniupnpd=1.0
Miniupnp Project Miniupnpd=1.1
Miniupnp Project Miniupnpd=1.2
Event History
Jan 31, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0229?
CVE-2013-0229 has a severity rating of medium due to its potential for causing denial of service.
2
How do I fix CVE-2013-0229?
To fix CVE-2013-0229, upgrade MiniUPnPd to version 1.4 or later.
3
What kind of attack can exploit CVE-2013-0229?
CVE-2013-0229 can be exploited through a crafted SSDP request that causes a buffer over-read.
4
Which versions of MiniUPnPd are affected by CVE-2013-0229?
CVE-2013-0229 affects MiniUPnPd versions up to and including 1.3.
5
What is the impact of an exploit for CVE-2013-0229?
Exploiting CVE-2013-0229 can lead to a denial of service, causing the affected service to crash.