CVE-2017-8798

CRITICAL

Miniupnpd - Memory Corruption

Title source: rule

Description

Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

Exploits (1)

exploitdb WORKING POC
by tintinweb · textdosmultiple
https://www.exploit-db.com/exploits/43501

Scores

CVSS v3 9.8
EPSS 0.2347
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-119
Status draft

Affected Products (6)

miniupnp_project/miniupnpd
miniupnp_project/miniupnpd
miniupnp_project/miniupnpd
miniupnp_project/miniupnpd
miniupnp_project/miniupnpd
miniupnp_project/miniupnpd

Timeline

Published May 11, 2017
Tracked Since Feb 18, 2026