CVE-2021-28302

NameCVE-2021-28302
DescriptionA stack overflow in pupnp 1.16.1 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs986833

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libupnp (PTS)stretch1:1.6.19+git20160116-1.2vulnerable
stretch (security)1:1.6.19+git20160116-1.2+deb9u1vulnerable
pupnp-1.8 (PTS)bullseye, sid, buster1:1.8.4-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libupnpsource(unstable)(unfixed)
pupnp-1.8source(unstable)(unfixed)986833

Notes

https://github.com/pupnp/pupnp/issues/249

Search for package or bug name: Reporting problems