Aleksandar Nikolic discovered a buffer overflow vulnerability in the XML parser functionality of the MiniUPnP library. A remote attacker could use this to cause a denial of service (application crash) or possibly execute arbitrary code with privileges of the user running an application that uses the MiniUPnP library.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1.6-3ubuntu2.14.04.2",
"binary_name": "libminiupnpc-dev"
},
{
"binary_version": "1.6-3ubuntu2.14.04.2",
"binary_name": "libminiupnpc8"
},
{
"binary_version": "1.6-3ubuntu2.14.04.2",
"binary_name": "miniupnpc"
}
]
}