miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting improper length validation in ParseHttpHeaders(), where the parsed length underflows to a large unsigned value when passed to memchr(), causing the process to scan memory far beyond the allocated HTTP request buffer.
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "miniupnpd",
"binary_version": "2.2.3-1ubuntu0.1~esm1"
},
{
"binary_name": "miniupnpd-iptables",
"binary_version": "2.2.3-1ubuntu0.1~esm1"
},
{
"binary_name": "miniupnpd-nftables",
"binary_version": "2.2.3-1ubuntu0.1~esm1"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "miniupnpd",
"binary_version": "2.3.4-1ubuntu0.1~esm1"
},
{
"binary_name": "miniupnpd-iptables",
"binary_version": "2.3.4-1ubuntu0.1~esm1"
},
{
"binary_name": "miniupnpd-nftables",
"binary_version": "2.3.4-1ubuntu0.1~esm1"
}
]
}{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "miniupnpd",
"binary_version": "2.3.9-2ubuntu0.1~esm1"
},
{
"binary_name": "miniupnpd-iptables",
"binary_version": "2.3.9-2ubuntu0.1~esm1"
},
{
"binary_name": "miniupnpd-nftables",
"binary_version": "2.3.9-2ubuntu0.1~esm1"
}
]
}