MiniUPnPd(版本 2.3.11 及更早版本)在启用 --strict 编译选项时,ProcessSSDPData() 函数中存在一个除零漏洞。未认证的本地网络攻击者可以利用该漏洞导致守护进程崩溃。攻击者只需向端口 1900 发送一个包含 MX: 0 和已知 ST 字段的单播 M-SEARCH 数据包,即可触发 SIGFPE 信号,从而导致 UPnP IGD 服务不可用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| miniupnp project | miniupnpd | ≤ 2.3.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| miniupnp project | miniupnpd | 0 ~ 2.3.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet