First published: Wed May 15 2019(Updated: )
The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MiniUPnP | =1.4 | |
MiniUPnP | =1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12106 is classified as a high severity vulnerability due to its potential to crash the process.
To fix CVE-2019-12106, upgrade MiniUPnP to version 1.6 or later where the vulnerability is patched.
CVE-2019-12106 affects users running MiniUPnP versions 1.4 and 1.5.
CVE-2019-12106 is a Use After Free vulnerability allowing remote attackers to crash the process.
Vulnerable systems are those utilizing MiniUPnP version 1.4 or 1.5, which includes various embedded devices and routers.