Vulnerability Name: | CVE-2016-3178 (CCN-111555) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2016-03-04 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2016-03-04 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2021-04-23 | ||||||||||||||||||||||||||||||||||||||||
Summary: | The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (out-of-bounds memory access and daemon crash) via vectors involving a negative length value. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) 4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-125 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-3178 Source: CCN Type: MiniSSDPd Web site MiniUPnP Project Source: CCN Type: oss-sec Mailing List, Mon, 7 Mar 2016 13:04:50 +0100 CVE Request: The minissdpd (v 1.2.20130907-3) is affected by an improper validation of array index weakness Source: CCN Type: oss-sec Mailing List, Wed, 16 Mar 2016 13:46:22 -0400 (EDT) Re: CVE Request: The minissdpd (v 1.2.20130907-3) is affected by an improper validation of array index weakness Source: CCN Type: Salva Peiro Security Advisory SPADV2016-02 The minissdpd daemon (1.2.20130907-3) is affected by an improper validation of array index weakness (CWE-129) Source: MISC Type: Patch, Third Party Advisory http://speirofr.appspot.com/files/advisory/SPADV-2016-02.md Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20160316 Re: CVE Request: The minissdpd (v 1.2.20130907-3) is affected by an improper validation of array index weakness Source: CCN Type: Debian Bug report logs - 816759 minissdpd: CVE-2016-3178 CVE-2016-3179 Source: CONFIRM Type: Issue Tracking, Mailing List, Patch, Third Party Advisory https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816759 Source: XF Type: UNKNOWN minissdpd-cve20163178-bo(111555) Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/miniupnp/miniupnp/commit/b238cade9a173c6f751a34acf8ccff838a62aa47 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-3178 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |