CVE-2016-8863
Debian Security Advisory 3736-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.
Desbordamiento de búfer basado en memoria dinámica en la función create_url_list en gena/gena_device.c en Portable UPnP SDK (también conocido como libupnp) en versiones anteriores a 1.6.21 permite a atacantes remotos provocar una denegación de servicio (caída) o posiblemente ejecutar código arbitrario a través de una URl válida seguida de una inválida en la cabecera CALLBACK de una petición SUBSCRIBE.
Multiple vulnerabilities have been found in libupnp, the worst of which could lead to the execution of arbitrary code. Versions less than 1.6.21 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-10-20 CVE Reserved
- 2016-12-16 CVE Published
- 2020-12-25 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/92849 | Vdb Entry | |
https://sourceforge.net/p/pupnp/bugs/133 | Issue Tracking | |
https://sourceforge.net/p/pupnp/code/ci/master/tree/ChangeLog | Release Notes | |
https://www.tenable.com/security/research/tra-2017-10 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://github.com/mephi42/CVE-2016-8863 | 2020-12-25 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201701-52 | 2017-11-03 | |
https://www.debian.org/security/2016/dsa-3736 | 2017-11-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libupnp Project Search vendor "Libupnp Project" | Libupnp Search vendor "Libupnp Project" for product "Libupnp" | <= 1.6.20 Search vendor "Libupnp Project" for product "Libupnp" and version " <= 1.6.20" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|