Lucene search

K
cveCertccCVE-2012-5964
HistoryJan 31, 2013 - 9:55 p.m.

CVE-2012-5964

2013-01-3121:55:01
CWE-119
certcc
web.nvd.nist.gov
41
cve-2012-5964
ssdp parser
buffer overflow
remote code execution
upnp
libupnp
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.924

Percentile

99.0%

Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) 1.3.1 allows remote attackers to execute arbitrary code via a long ServiceType (aka urn service) field in a UDP packet.

Affected configurations

Nvd
Node
portable_sdk_for_upnp_projectportable_sdk_for_upnpMatch1.3.1
VendorProductVersionCPE
portable_sdk_for_upnp_projectportable_sdk_for_upnp1.3.1cpe:/a:portable_sdk_for_upnp_project:portable_sdk_for_upnp:1.3.1:::

References

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.924

Percentile

99.0%