The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.5"
}
]
}[
{
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2019-12106-18e19ac1",
"target": {
"file": "minissdpd/minissdpd.c",
"function": "updateDevice"
},
"digest": {
"length": 1787.0,
"function_hash": "49626815456841716209215577197332225879"
},
"signature_version": "v1",
"source": "https://github.com/miniupnp/miniupnp/commit/cd506a67e174a45c6a202eff182a712955ed6d6f"
},
{
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2019-12106-a81ca291",
"target": {
"file": "minissdpd/minissdpd.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"136228493942524335642480519156147028320",
"214698895325830240883302560531919787267",
"282269370337803121966929167125174309566",
"15209298193392725639910941306136385751"
]
},
"signature_version": "v1",
"source": "https://github.com/miniupnp/miniupnp/commit/cd506a67e174a45c6a202eff182a712955ed6d6f"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12106.json"