The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak information from the heap due to improper validation of an snprintf return value.
The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Miniupnpd | Miniupnp.free | * | 2.1 (including) |
Miniupnpd | Ubuntu | bionic | * |
Miniupnpd | Ubuntu | cosmic | * |
Miniupnpd | Ubuntu | disco | * |
Miniupnpd | Ubuntu | trusty | * |
Miniupnpd | Ubuntu | xenial | * |