PublicDateAtUSN: 2017-05-10 Candidate: CVE-2017-8798 PublicDate: 2017-05-11 01:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8798 https://github.com/tintinweb/pub/blob/master/pocs/cve-2017-8798/Readme.md https://ubuntu.com/security/notices/USN-3298-1 https://ubuntu.com/security/notices/USN-3298-2 Description: Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact. Ubuntu-Description: Notes: Bugs: https://launchpad.net/bugs/1690816 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862273 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_miniupnpc: upstream: https://github.com/miniupnp/miniupnp/commit/f0f1f4b22d6a98536377a1bb07e7c20e4703d229 upstream_miniupnpc: released (1.9.20140610-3) precise/esm_miniupnpc: DNE trusty_miniupnpc: released (1.6-3ubuntu2.14.04.3) trusty/esm_miniupnpc: DNE (trusty was released [1.6-3ubuntu2.14.04.3]) vivid/stable-phone-overlay_miniupnpc: DNE vivid/ubuntu-core_miniupnpc: DNE xenial_miniupnpc: released (1.9.20140610-2ubuntu2.16.04.1) esm-infra/xenial_miniupnpc: released (1.9.20140610-2ubuntu2.16.04.1) yakkety_miniupnpc: released (1.9.20140610-2ubuntu2.16.10.1) zesty_miniupnpc: released (1.9.20140610-2ubuntu2.17.04.1) devel_miniupnpc: released (1.9.20140610-3ubuntu1)