Vulnerability record · CVE-2016-8863 · published 7 March 2017
CVE-2016-8863: Libupnp project libupnp memory buffer overflow vulnerability
LLibupnp Project · Libupnp
Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.
Description
Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/92849 | |
| https://security.gentoo.org/glsa/201701-52 | |
| https://sourceforge.net/p/pupnp/bugs/133/ | Issue TrackingThird Party Advisory |
| https://sourceforge.net/p/pupnp/code/ci/master/tree/ChangeLog | Release NotesThird Party Advisory |
| https://www.debian.org/security/2016/dsa-3736 | Third Party Advisory |
| https://www.tenable.com/security/research/tra-2017-10 | |
| http://www.securityfocus.com/bid/92849 | |
| https://security.gentoo.org/glsa/201701-52 | |
| https://sourceforge.net/p/pupnp/bugs/133/ | Issue TrackingThird Party Advisory |
| https://sourceforge.net/p/pupnp/code/ci/master/tree/ChangeLog | Release NotesThird Party Advisory |
| https://www.debian.org/security/2016/dsa-3736 | Third Party Advisory |
| https://www.tenable.com/security/research/tra-2017-10 |
Track CVE-2016-8863 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-8863), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.