5
CVSSv2

CVE-2021-28302

Published: 12/03/2021 Updated: 22/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pupnp project pupnp

Vendor Advisories

Debian Bug report logs - #986833 pupnp-18: CVE-2021-28302 Package: src:pupnp-18; Maintainer for src:pupnp-18 is James Cowgill <jcowgill@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 12 Apr 2021 15:06:01 UTC Severity: important Tags: security, upstream Found in version pupnp-18/1:1 ...
A stack overflow in libupnp 1142 can cause denial of service through the Parser_parseDocument() function ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash ...