Loading
Generated remediation guidance and an executive summary. No account required.
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.
Use CWE-476, Libupnp Project vendor hub and Libupnp product page to widen CVE-2020-13848 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2012-5961, CVE-2012-5958 and CVE-2016-8863 for nearby disclosures in the same product family.