Lucene search

K
cveCertccCVE-2012-5963
HistoryJan 31, 2013 - 9:55 p.m.

CVE-2012-5963

2013-01-3121:55:01
CWE-119
certcc
web.nvd.nist.gov
48
cve-2012-5963
stack-based buffer overflow
unique_service_name
ssdp_server.c
libupnp
upnp
sdk
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.924

Percentile

99.0%

Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code via a long UDN (aka uuid) field within a string that lacks a :: (colon colon) in a UDP packet.

Affected configurations

Nvd
Node
portable_sdk_for_upnp_projectportable_sdk_for_upnpMatch1.3.1
VendorProductVersionCPE
portable_sdk_for_upnp_projectportable_sdk_for_upnp1.3.1cpe:/a:portable_sdk_for_upnp_project:portable_sdk_for_upnp:1.3.1:::

References

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.924

Percentile

99.0%