Published: 15/05/2019 Updated: 30/05/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd up to and including 2.1 allows a remote malicious user to leak information from the heap due to improper validation of an snprintf return value.

Vulnerability Trend

Affected Products

Vendor Product Versions

Vendor Advisories

Debian Bug report logs - #930050 miniupnpd: CVE-2019-12107 CVE-2019-12108 CVE-2019-12109 CVE-2019-12110 CVE-2019-12111 Package: src:miniupnpd; Maintainer for src:miniupnpd is Thomas Goirand <zigo@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Jun 2019 07:42:02 UTC Severity: grave Tag ...