Out-of-bounds read in miniupnpd - CVE-2013-0229
Published: January 31, 2013 / Updated: August 11, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4. A remote attacker can perform a denial of service (service crash) via a crafted request that triggers a buffer over-read.
Affected software
How to mitigate CVE-2013-0229
Links to Public Exploits and PoC-codes
- Exploit #4413 - INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service (August 11, 2020)
- Exploit #4410 - MiniUPnP 1.4 - Multiple Denial of Service Vulnerabilities (August 11, 2020)
- Exploit #4131 - MiniUPnPd 1.4 Denial of Service (DoS) Exploit (August 11, 2020)
- Exploit #4121 - UPnP SSDP M-SEARCH Information Discovery (August 11, 2020)