CVE-2016-6255: High severity debian linux vulnerability
Published Jul 20, 2016
·Updated
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.
Affected Software
3 affected components
debian/libupnp
Debian Debian Linux=8.0
Libupnp Project Libupnp<=1.6.20
Remediation
Patch Available
Patch Available
Event History
Jul 20, 2016
Data Sourced
09:06 AM
SeverityAffected Software
Mar 7, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6255?
CVE-2016-6255 is classified as a medium severity vulnerability due to its potential for arbitrary file writing in the webroot.
2
How do I fix CVE-2016-6255?
To mitigate CVE-2016-6255, update the Portable UPnP SDK (libupnp) to version 1.6.21 or later.
3
What types of systems are affected by CVE-2016-6255?
CVE-2016-6255 affects systems using Portable UPnP SDK versions prior to 1.6.21, particularly on Debian 8.0.
4
Can CVE-2016-6255 be exploited remotely?
Yes, CVE-2016-6255 allows remote attackers to exploit the vulnerability through a crafted POST request.
5
What are the potential impacts of CVE-2016-6255?
Exploitation of CVE-2016-6255 can lead to unauthorized write access to arbitrary files within the webroot.