Oval Definition:oval:com.ubuntu.xenial:def:201662550000000
Revision Date:2017-03-07Version:1
Title:CVE-2016-6255 on Ubuntu 16.04 LTS (xenial) - high.
Description:Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler. Matthew Garrett discovered that libupnp mishandled POST requests by default. An attacker could use this vulnerability to write files to arbitrary locations in the victim's filesystem, possibly as root.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-6255
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND libupnp package in xenial is affected and needs fixing.
  • BACK