USN-4494-1: GUPnP vulnerability

15 September 2020

gupnp could be made to expose sensitive information or perform network attacks if it received specially crafted network traffic.

Releases

Packages

  • gupnp - framework for creating UPnP devices and control points

Details

It was discovered that GUPnP incorrectly handled certain subscription
requests. A remote attacker could possibly use this issue to exfiltrate
data or use GUPnP to perform DDoS attacks.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 20.04

After a standard system update you need to reboot your computer to make
all the necessary changes.

References