Lucene search

K
cve[email protected]CVE-2012-5958
HistoryJan 31, 2013 - 9:55 p.m.

CVE-2012-5958

2013-01-3121:55:01
CWE-119
web.nvd.nist.gov
202
cve-2012-5958
buffer overflow
ssdp parser
vulnerability
upnp
libupnp
remote code execution
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.974 High

EPSS

Percentile

99.9%

Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a UDP packet with a crafted string that is not properly handled after a certain pointer subtraction.

Affected configurations

NVD
Node
libupnp_projectlibupnpRange1.6.17
OR
libupnp_projectlibupnpMatch1.4.0
OR
libupnp_projectlibupnpMatch1.4.1
OR
libupnp_projectlibupnpMatch1.4.2
OR
libupnp_projectlibupnpMatch1.4.3
OR
libupnp_projectlibupnpMatch1.4.4
OR
libupnp_projectlibupnpMatch1.4.5
OR
libupnp_projectlibupnpMatch1.4.6
OR
libupnp_projectlibupnpMatch1.4.7
OR
libupnp_projectlibupnpMatch1.6.0
OR
libupnp_projectlibupnpMatch1.6.1
OR
libupnp_projectlibupnpMatch1.6.2
OR
libupnp_projectlibupnpMatch1.6.3
OR
libupnp_projectlibupnpMatch1.6.4
OR
libupnp_projectlibupnpMatch1.6.5
OR
libupnp_projectlibupnpMatch1.6.6
OR
libupnp_projectlibupnpMatch1.6.7
OR
libupnp_projectlibupnpMatch1.6.8
OR
libupnp_projectlibupnpMatch1.6.9
OR
libupnp_projectlibupnpMatch1.6.10
OR
libupnp_projectlibupnpMatch1.6.11
OR
libupnp_projectlibupnpMatch1.6.12
OR
libupnp_projectlibupnpMatch1.6.13
OR
libupnp_projectlibupnpMatch1.6.14
OR
libupnp_projectlibupnpMatch1.6.15
OR
libupnp_projectlibupnpMatch1.6.16

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.974 High

EPSS

Percentile

99.9%