First published: Thu Jan 31 2013(Updated: )
Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a SOAPAction header that lacks a " (double quote) character, a different vulnerability than CVE-2013-0230.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MiniUPnP | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1462 has a high severity due to its potential to cause denial of service.
To fix CVE-2013-1462, upgrade MiniUPnPd to a later version that addresses this vulnerability.
CVE-2013-1462 specifically affects MiniUPnPd version 1.0.
CVE-2013-1462 allows remote attackers to execute a denial of service attack through a malformed SOAPAction header.
Yes, CVE-2013-1462 can be exploited remotely by sending specially crafted requests to vulnerable systems.