Lucene search

K
cveCertccCVE-2012-5961
HistoryJan 31, 2013 - 9:55 p.m.

CVE-2012-5961

2013-01-3121:55:01
CWE-119
certcc
web.nvd.nist.gov
48
cve-2012-5961
stack-based buffer overflow
unique_service_name
ssdp_server.c
ssdp parser
portable sdk
upnp devices
libupnp
intel sdk
remote code execution
udn
udp packet
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.924

Percentile

99.0%

Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code via a long UDN (aka device) field in a UDP packet.

Affected configurations

Nvd
Node
libupnp_projectlibupnpMatch1.3.1
VendorProductVersionCPE
libupnp_projectlibupnp1.3.1cpe:/a:libupnp_project:libupnp:1.3.1:::

References

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.924

Percentile

99.0%