MiniUPnP MiniUPnPd HTTP Service SOAPAction Handler ExecuteSoapAction Function NULL Pointer Dereference Remote DoS Vulnerability
4 Apr. 2013
Summary
MiniUPnP miniUPnPd HTTP service SOAPaction handler executesoapaction function NULL pointer dereference remote suffers from denial of service vulnerability
Credit:
The information has been provided by Rapid7 - Rapid7, LLC .
MiniUPnP contains a NULL pointer derference flaw in the MiniUPnPd HTTP Service that may allow a remote denial of service. The issue is triggered when handling a SOAPaction header that lacks a '#' symbol sent via the ExecuteSoapAction function. With a specially crafted action, a remote attacker can cause the service to crash.