Release date:
Updated on: 2013-02-02
Affected Systems:
Broadcom UPnP
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57649
Broadcom UPnP is a universal plug-and-play protocol.
The SetConnectionType () function of the Broadcom UPnP Stack has the format string vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code.
<* Source: Leon Juranic (ljuranic@LSS.hr)
Link: http://xforce.iss.net/xforce/xfdb/81712
Http://packetstormsecurity.com/files/119935/Broadcom-UPnP-Remote-Preauth-Root-Code-Execution.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Broadcom
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://zh-cn.broadcom.com/