Bugzilla – Bug 1172625
VUL-0: CVE-2020-13848: libupnp: DoS via crafted SSDP message
Last modified: 2020-06-16 13:52:05 UTC
CVE-2020-13848 Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-13848 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-13848.html https://github.com/pupnp/pupnp/commit/c805c1de1141cb22f74c0d94dd5664bda37398e0 https://github.com/pupnp/pupnp/issues/177 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13848
This is an autogenerated message for OBS integration: This bug (1172625) was mentioned in https://build.opensuse.org/request/show/813025 Factory / libupnp https://build.opensuse.org/request/show/813027 15.1 / libupnp
fix was submitted and accepted
openSUSE-SU-2020:0821-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1172625 CVE References: CVE-2020-13848 Sources used: openSUSE Backports SLE-15-SP1 (src): libupnp-1.6.25-bp151.4.3.1
openSUSE-SU-2020:0805-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1172625 CVE References: CVE-2020-13848 Sources used: openSUSE Leap 15.1 (src): libupnp-1.6.25-lp151.3.3.1