CVE-2016-3179: Use After Free
Published Mar 24, 2017
·Updated
The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (invalid free and daemon crash) via vectors related to error handling.
Affected Software
2 affected componentsFixes available
debian/minissdpd
1.5.20190824-11.6.0-11.6.0-2
Miniupnp Project Minissdpd=1.2.20130907-3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3179?
CVE-2016-3179 has a severity rating indicating a denial of service vulnerability that can cause the daemon to crash.
2
How do I fix CVE-2016-3179?
To fix CVE-2016-3179, upgrade to at least minissdpd version 1.5.20190824-1 or 1.6.0-1.
3
What software is affected by CVE-2016-3179?
CVE-2016-3179 affects MiniSSDPd version 1.2.20130907-3.
4
Can CVE-2016-3179 be exploited remotely?
CVE-2016-3179 is primarily a local vulnerability that does not allow remote exploitation.
5
What does CVE-2016-3179 allow an attacker to do?
CVE-2016-3179 allows local users to cause a denial of service through improper error handling.