USN-8731-1: MiniUPnPd vulnerability
Ubuntu issued USN-8731-1 fixing a MiniUPnPd integer underflow allowing remote DoS or information disclosure via malformed SOAPAction headers.
Ubuntu released USN-8731-1 to address an integer underflow vulnerability in MiniUPnPd's SOAPAction header parsing. A remote attacker could send a malformed SOAPAction header containing a single quote to trigger a denial of service or information disclosure. MiniUPnPd is a lightweight UPnP daemon widely deployed on routers and gateways.
- Fix shipped in Ubuntu security notice USN-8731-1
- Trigger requires a malformed SOAPAction header containing a single quote
- Impact limited to denial of service or information disclosure
It was discovered that MiniUPnPd contained an integer underflow vulnerability in SOAPAction header parsing. A remote attacker could use this issue to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote.
This source does not provide full text. Read it at ubuntu.com.