Aleksandar Nikolic discovered a buffer overflow vulnerability in the XML parser functionality of the MiniUPnP library. A remote attacker could use this to cause a denial of service (application crash) or possibly execute arbitrary code with privileges of the user running an application that uses the MiniUPnP library.
{ "binaries": [ { "binary_name": "libminiupnpc-dev", "binary_version": "1.6-3ubuntu2.14.04.2" }, { "binary_name": "libminiupnpc8", "binary_version": "1.6-3ubuntu2.14.04.2" }, { "binary_name": "miniupnpc", "binary_version": "1.6-3ubuntu2.14.04.2" } ], "availability": "No subscription required" }