A heap buffer overflow vulnerability was found in libupnp. This vulnerability might allow for a wide range of impacts, from denial of service to remote code execution.
Upstream bug:
https://sourceforge.net/p/pupnp/bugs/133/
CVE assignment:
http://seclists.org/oss-sec/2016/q4/200
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.