MGASA-2018-0250

Source
https://advisories.mageia.org/MGASA-2018-0250.html
Import Source
https://advisories.mageia.org/MGASA-2018-0250.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0250
Related
Published
2018-05-19T20:56:45Z
Modified
2018-05-19T20:23:09Z
Summary
Updated miniupnpc packages fix security vulnerability
Details

It was discovered that miniupnpc contained a heap buffer overflow in parseelt (minixml.c - no CVE assigned).

It was discovered that miniupnpc also contained a memory corruption (invalid read, SIGSEGV) in NameValueParserEndElt (upnpreplyparse.c) while handling two consecutive malformed SOAP requests (CVE-2017-1000494).

References
Credits

Affected packages

Mageia:6 / miniupnpc

Package

Name
miniupnpc
Purl
pkg:rpm/mageia/miniupnpc?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.20170509-1.1.mga6

Ecosystem specific

{
    "section": "core"
}