Oval Definition:oval:com.ubuntu.bionic:def:201662550000000
Revision Date:2017-03-07Version:1
Title:CVE-2016-6255 on Ubuntu 18.04 LTS (bionic) - high.
Description:Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler. Matthew Garrett discovered that libupnp mishandled POST requests by default. An attacker could use this vulnerability to write files to arbitrary locations in the victim's filesystem, possibly as root.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-6255
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND libupnp package in bionic, is related to the CVE in some way and has been fixed (note: '1:1.6.22-1').
  • BACK