CVE-2012-5958

Description

Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable SDK for UPnP Devices (aka libupnp, formerly the Intel SDK for UPnP devices) before 1.6.18 allows remote attackers to execute arbitrary code via a UDP packet with a crafted string that is not properly handled after a certain pointer subtraction.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
88.697

Associated Vulnerability

VulnerabilityOS Platform
Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities For Cisco Small Business RV Series RoutersNCM
Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities For Cisco Small Business Video Monitoring SystemNCM
Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities For Cisco Small Business SA500 Series Security AppliancesNCM
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2012-5958)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705925Security Update for Cisco Small Business RV Series Routers 1.0.3.16

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234