Vulnerability Description
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Miniupnp Project | Miniupnpc | <= 1.9 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 12.04 |
| Opensuse | Leap | 42.1 |
| Opensuse | Opensuse | 13.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00122.htmlMailing ListThird Party Advisory
- http://talosintel.com/reports/TALOS-2015-0035/Exploit
- http://www.debian.org/security/2015/dsa-3379Third Party Advisory
- http://www.securityfocus.com/bid/77306Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2780-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2780-2Third Party Advisory
- https://github.com/miniupnp/miniupnp/blob/master/miniupnpc/Changelog.txtThird Party Advisory
- https://github.com/miniupnp/miniupnp/commit/79cca974a4c2ab1199786732a67ff6d89805Third Party Advisory
- https://security.gentoo.org/glsa/201801-08Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00122.htmlMailing ListThird Party Advisory
- http://talosintel.com/reports/TALOS-2015-0035/Exploit
- http://www.debian.org/security/2015/dsa-3379Third Party Advisory
- http://www.securityfocus.com/bid/77306Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2780-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2780-2Third Party Advisory
FAQ
What is CVE-2015-6031?
CVE-2015-6031 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) a...
How severe is CVE-2015-6031?
CVE-2015-6031 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6031?
Check the references section above for vendor advisories and patch information. Affected products include: Miniupnp Project Miniupnpc, Debian Debian Linux, Canonical Ubuntu Linux, Opensuse Leap, Opensuse Opensuse.