vendor:
miniupnpd
by:
b1ack0wl
7.5
CVSS
HIGH
Out-of-Bounds Read
125
CWE
Product Name: miniupnpd
Affected Version From: v2.1
Affected Version To: v2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:miniupnp:miniupnpd
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
miniupnpd <= v2.1 read out-of-bounds PoC
This exploit is a proof-of-concept for a vulnerability in miniupnpd <= v2.1. The vulnerability allows an attacker to read out-of-bounds data from the vulnerable device. The exploit sends a SUBSCRIBE request with a specially crafted Callback header to the vulnerable device. The device then responds with a NOTIFY request containing the out-of-bounds data. The attacker can then read the data from the NOTIFY request.
Mitigation:
Upgrade to the latest version of miniupnpd.