USN-2780-2: MiniUPnP vulnerability
23 October 2015
An application using the MiniUPnP library could be made to crash or run programs as your login if it received specially crafted network traffic.
- miniupnpc - UPnP IGD client lightweight library
USN-2780-1 fixed a vulnerability in the MiniUPnP library in Ubuntu
12.04 LTS, Ubuntu 14.04 LTS, and Ubuntu 15.04. This update provides
the corresponding update for Ubuntu 15.10.
Original advisory details:
Aleksandar Nikolic discovered a buffer overflow vulnerability in the
XML parser functionality of the MiniUPnP library. A remote attacker
could use this to cause a denial of service (application crash) or
possibly execute arbitrary code with privileges of the user running
an application that uses the MiniUPnP library.