CVE-2019-12106: Use After Free
Published May 15, 2019
·Updated
The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
Affected Software
2 affected components
Miniupnp Project Miniupnpd=1.4
Miniupnp Project Miniupnpd=1.5
Remediation
Event History
May 15, 2019
CVE Published
via MITRE·10:22 PM
Data Sourced
via MITRE·10:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12106?
CVE-2019-12106 is classified as a high severity vulnerability due to its potential to crash the process.
2
How do I fix CVE-2019-12106?
To fix CVE-2019-12106, upgrade MiniUPnP to version 1.6 or later where the vulnerability is patched.
3
Who is affected by CVE-2019-12106?
CVE-2019-12106 affects users running MiniUPnP versions 1.4 and 1.5.
4
What type of vulnerability is CVE-2019-12106?
CVE-2019-12106 is a Use After Free vulnerability allowing remote attackers to crash the process.
5
What systems are vulnerable to CVE-2019-12106?
Vulnerable systems are those utilizing MiniUPnP version 1.4 or 1.5, which includes various embedded devices and routers.