DEBIAN-CVE-2021-28302

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2021-28302
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-28302.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2021-28302
Upstream
Published
2021-03-12T15:15:14Z
Modified
2025-09-18T05:18:38Z
Summary
[none]
Details

A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the ParserparseDocument() function. ixmlNodefree() will release a child node recursively, which will consume stack space and lead to a crash.

References

Affected packages

Debian:11 / pupnp-1.8

Package

Name
pupnp-1.8
Purl
pkg:deb/debian/pupnp-1.8?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / pupnp-1.8

Package

Name
pupnp-1.8
Purl
pkg:deb/debian/pupnp-1.8?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}