First published: Fri Nov 01 2019(Updated: )
MiniUPnPd has information disclosure use of snprintf()
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/miniupnpd | 2.2.1-1 2.3.1-1 2.3.7-1 | |
MiniUPnP | =1.8 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2600 is classified as a medium severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2013-2600, users should upgrade MiniUPnPd to the latest version as specified in the remediation.
CVE-2013-2600 affects MiniUPnPd versions 1.8, 2.2.1-1, 2.3.1-1, and 2.3.7-1.
Yes, CVE-2013-2600's information disclosure can potentially be leveraged to facilitate further attacks.
CVE-2013-2600 is particularly associated with Debian systems, including Debian versions 8.0, 9.0, and 10.0.