CVE Database
/

CVE-2016-8863

Back to search

CVE-2016-8863

Published: Mar 7, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-201701-52
vendor-advisory
x_refsource_GENTOO
DSA-3736
vendor-advisory
x_refsource_DEBIAN
92849
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now