VulnerabilityModified
CVE-2016-6255
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.
HIGH 7.5EPSS 26.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 26.62% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- debian/debian linux · libupnp project/libupnp
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2016/dsa-3736Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/07/18/13Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/07/20/5Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/92050Third Party Advisory, VDB Entry
- https://github.com/mjg59/pupnp-code/commit/be0a01bdb83395d9f3a5ea09c1308a4f1a972cbdIssue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201701-52
- https://sourceforge.net/p/pupnp/code/ci/master/tree/ChangeLogRelease Notes, Third Party Advisory
- https://twitter.com/mjg59/status/755062278513319936Third Party Advisory
- https://www.exploit-db.com/exploits/40589/
- https://www.tenable.com/security/research/tra-2017-10
- http://www.debian.org/security/2016/dsa-3736Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/07/18/13Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/07/20/5Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/92050Third Party Advisory, VDB Entry
- https://github.com/mjg59/pupnp-code/commit/be0a01bdb83395d9f3a5ea09c1308a4f1a972cbdIssue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201701-52
- https://sourceforge.net/p/pupnp/code/ci/master/tree/ChangeLogRelease Notes, Third Party Advisory
- https://twitter.com/mjg59/status/755062278513319936Third Party Advisory
- https://www.exploit-db.com/exploits/40589/
- https://www.tenable.com/security/research/tra-2017-10
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.