ALT-PU-2021-4751-1
Package libupnp updated to version 1.14.12-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
BDU:2021-01679
Уязвимость функции Parser_parseDocument() набора средств для UPnP устройств PUPnP, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2023-11-21
BDU:2021-03726
Уязвимость функций FindServiceControlURLPath и FindServiceEventURLPath библиотеки для разработки программного обеспечения Portable UPnP SDK, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-13848
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00033.html
- https://github.com/pupnp/pupnp/commit/c805c1de1141cb22f74c0d94dd5664bda37398e0
- https://github.com/pupnp/pupnp/issues/177
- https://lists.debian.org/debian-lts-announce/2020/06/msg00006.html
- https://lists.debian.org/debian-lts-announce/2021/03/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00033.html
- https://github.com/pupnp/pupnp/commit/c805c1de1141cb22f74c0d94dd5664bda37398e0
- https://github.com/pupnp/pupnp/issues/177
- https://lists.debian.org/debian-lts-announce/2020/06/msg00006.html
- https://lists.debian.org/debian-lts-announce/2021/03/msg00007.html
Modified: 2024-11-21
CVE-2021-28302
A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash.