Get a Pentest and security assessment of your IT network.

Cyber Security

Cisco MiniUPnP Stack Smashing Protection Attack

Cisco s Talos security intelligence and research group found and privately disclosed a serious and trivially exploitable client-side bug in MiniUPnP. A successful exploit gives an attacker remote-code execution capabilities on a device, and quite likely further access inside the local network. The vulnerability in the library (CVE-2015-6031) is a buffer overflow, a bug in the XML parsing code in the IGDstartelt function. The exploit bypasses a mitigation in place called Stack Smashing Protection (SSP), which protects vulnerable buffers in a stack with a canary.

Source: https://threatpost.com/miniupnp-vulnerability-clears-way-for-stack-smashing-attack/116030/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security