USN-4494-1: GUPnP vulnerability
15 September 2020
gupnp could be made to expose sensitive information or perform network attacks if it received specially crafted network traffic.
Releases
Packages
- gupnp - framework for creating UPnP devices and control points
Details
It was discovered that GUPnP incorrectly handled certain subscription
requests. A remote attacker could possibly use this issue to exfiltrate
data or use GUPnP to perform DDoS attacks.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
After a standard system update you need to reboot your computer to make
all the necessary changes.
References
Related notices
- USN-4722-1: minidlna
- USN-4734-1: wpagui, wpasupplicant-udeb, wpa, hostapd, wpasupplicant
- USN-4734-2: wpagui, wpasupplicant-udeb, wpa, hostapd, wpasupplicant