Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4:6.4.0+dfsg-3ubuntu0.1~esm1", "binary_name": "digikam" }, { "binary_version": "4:6.4.0+dfsg-3ubuntu0.1~esm1", "binary_name": "digikam-data" }, { "binary_version": "4:6.4.0+dfsg-3ubuntu0.1~esm1", "binary_name": "digikam-dbgsym" }, { "binary_version": "4:6.4.0+dfsg-3ubuntu0.1~esm1", "binary_name": "digikam-private-libs" }, { "binary_version": "4:6.4.0+dfsg-3ubuntu0.1~esm1", "binary_name": "digikam-private-libs-dbgsym" }, { "binary_version": "4:6.4.0+dfsg-3ubuntu0.1~esm1", "binary_name": "showfoto" }, { "binary_version": "4:6.4.0+dfsg-3ubuntu0.1~esm1", "binary_name": "showfoto-dbgsym" } ] }