The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
{ "vanir_signatures": [ { "source": "https://github.com/miniupnp/miniupnp/commit/cd506a67e174a45c6a202eff182a712955ed6d6f", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 1787.0, "function_hash": "49626815456841716209215577197332225879" }, "target": { "file": "minissdpd/minissdpd.c", "function": "updateDevice" }, "id": "CVE-2019-12106-18e19ac1" }, { "source": "https://github.com/miniupnp/miniupnp/commit/cd506a67e174a45c6a202eff182a712955ed6d6f", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "136228493942524335642480519156147028320", "214698895325830240883302560531919787267", "282269370337803121966929167125174309566", "15209298193392725639910941306136385751" ] }, "target": { "file": "minissdpd/minissdpd.c" }, "id": "CVE-2019-12106-a81ca291" } ] }