Lucene search

K
cve[email protected]CVE-2015-6031
HistoryNov 02, 2015 - 7:59 p.m.

CVE-2015-6031

2015-11-0219:59:14
CWE-119
web.nvd.nist.gov
48
miniupnp
buffer overflow
cve-2015-6031
remote attackers
denial of service
arbitrary code
xml element
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.0%

Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an “oversized” XML element name.

Affected configurations

NVD
Node
miniupnp_projectminiupnpcRange1.9
OR
miniupnp_projectminiupnpcMatch1.92014-02-03
OR
miniupnp_projectminiupnpcMatch1.92014-02-05
OR
miniupnp_projectminiupnpcMatch1.92014-05-15
OR
miniupnp_projectminiupnpcMatch1.92014-06-10
OR
miniupnp_projectminiupnpcMatch1.92014-07-01
OR
miniupnp_projectminiupnpcMatch1.92014-09-06
OR
miniupnp_projectminiupnpcMatch1.92014-09-11
OR
miniupnp_projectminiupnpcMatch1.92014-11-05
OR
miniupnp_projectminiupnpcMatch1.92014-11-13
OR
miniupnp_projectminiupnpcMatch1.92014-11-17
OR
miniupnp_projectminiupnpcMatch1.92015-04-27
OR
miniupnp_projectminiupnpcMatch1.92015-04-30
OR
miniupnp_projectminiupnpcMatch1.92015-05-22
OR
miniupnp_projectminiupnpcMatch1.92015-06-16
OR
miniupnp_projectminiupnpcMatch1.92015-07-15
OR
miniupnp_projectminiupnpcMatch1.92015-07-22
OR
miniupnp_projectminiupnpcMatch1.92015-07-23
OR
miniupnp_projectminiupnpcMatch1.92015-08-16
OR
miniupnp_projectminiupnpcMatch1.92015-08-27
OR
miniupnp_projectminiupnpcMatch1.92015-08-28
OR
miniupnp_projectminiupnpcMatch1.92015-09-15
Node
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch15.04
Node
opensuseleapMatch42.1
OR
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.0%