The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "minissdpd", "binary_version": "1.2.20130907-3+deb8u2build0.16.04.1" }, { "binary_name": "minissdpd-dbgsym", "binary_version": "1.2.20130907-3+deb8u2build0.16.04.1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "minissdpd", "binary_version": "1.5.20190210-1" }, { "binary_name": "minissdpd-dbgsym", "binary_version": "1.5.20190210-1" } ] }