CVE-2016-8863

NameCVE-2016-8863
DescriptionHeap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-747-1, DLA-748-1, DSA-3736-1
NVD severityhigh (attack range: remote)
Debian Bugs842093

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libupnp (PTS)wheezy1:1.6.17-1.2vulnerable
wheezy (security)1:1.6.17-1.2+deb7u2fixed
jessie, jessie (security)1:1.6.19+git20141001-1+deb8u1fixed
stretch1:1.6.19+git20160116-1.2fixed
buster, sid1:1.6.22-1fixed
libupnp4 (PTS)wheezy1.8.0~svn20100507-1.2vulnerable
wheezy (security)1.8.0~svn20100507-1.2+deb7u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libupnpsource(unstable)1:1.6.19+git20160116-1.2high842093
libupnpsourcejessie1:1.6.19+git20141001-1+deb8u1highDSA-3736-1
libupnpsourcewheezy1:1.6.17-1.2+deb7u2highDLA-747-1
libupnp4source(unstable)(unfixed)high
libupnp4sourcewheezy1.8.0~svn20100507-1.2+deb7u1highDLA-748-1

Notes

https://sourceforge.net/p/pupnp/bugs/133/
Patch: https://sourceforge.net/p/pupnp/bugs/_discuss/thread/f2781a77/d8a2/attachment/0001-Fix-out-of-bound-access-in-create_url_list-CVE-2016-.patch

Search for package or bug name: Reporting problems