First published: Fri Mar 04 2016(Updated: )
The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (out-of-bounds memory access and daemon crash) via vectors involving a negative length value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/minissdpd | <=1.1.20120121-1<=1.2.20130907-3 | 1.2.20130907-3.2 1.2.20130907-3+deb8u1 |
debian/minissdpd | 1.5.20190824-1 1.6.0-1 1.6.0-2 | |
MiniUPnP | =1.2.20130907-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3178 has a severity rating that indicates it can lead to a denial of service due to out-of-bounds memory access.
To fix CVE-2016-3178, update to MiniSSDPd versions 1.5.20190824-1, 1.6.0-1, or later.
MiniSSDPd versions up to and including 1.2.20130907-3 are affected by CVE-2016-3178.
Yes, local users can exploit CVE-2016-3178 to cause a denial of service by manipulating the processRequest function.
CVE-2016-3178 is categorized as a denial of service vulnerability.