vendor:
AllShare
by:
Luigi Auriemma
7,5
CVSS
HIGH
NULL Pointer Dereference
476
CWE
Product Name: AllShare
Affected Version From: <= 2.1.1.0
Affected Version To: <= 2.1.1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:samsung:allshare
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Samsung AllShare NULL Pointer Remote Crash
The DLNA server listening on port 9500 can be crashed remotely due to a NULL pointer dereference caused by the failed allocation of a big amount of memory specified in Content-Length and the tentative of copying data in this NULL buffer. If Content-Length is between 4294967262 and 4294967293 the effect will be an unhandled exception in MSVCR90.calloc. The vulnerability is located in the lupin3 (libpin3) library.
Mitigation:
No fix.