CVE-2016-8863: Buffer Overflow
A heap buffer overflow vulnerability was found in libupnp. This vulnerability might allow for a wide range of impacts, from denial of service to remote code execution.
Upstream bug:
https://sourceforge.net/p/pupnp/bugs/133/
CVE assignment:
http://seclists.org/oss-sec/2016/q4/200
Other sources
Heap-based buffer overflow in the createurllist function in gena/genadevice.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8863?
CVE-2016-8863 is a high-severity vulnerability due to its potential for remote code execution and denial of service.
What type of vulnerability is CVE-2016-8863?
CVE-2016-8863 is classified as a heap buffer overflow vulnerability.
How do I fix CVE-2016-8863?
To fix CVE-2016-8863, update to a patched version of libupnp that addresses this vulnerability.
Which software is affected by CVE-2016-8863?
CVE-2016-8863 affects libupnp versions up to and including 1.6.20, as well as Debian GNU/Linux 8.0.
Can CVE-2016-8863 be exploited remotely?
Yes, CVE-2016-8863 can be exploited remotely, potentially allowing attackers to execute arbitrary code.