CVE-2019-14323: Simple Service Discovery Protocol Responder Project Simple Service Discovery Protocol Responder
High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.
SSDP Responder 1.x through 1.5 mishandles incoming network messages, leading to a stack-based buffer overflow by 1 byte. This results in a crash of the server, but only when strict stack checking is enabled. This is caused by an off-by-one error in ssdp_recv in ssdpd.c.
Affected products
- Simple Service Discovery Protocol Responder Project Simple Service Discovery Protocol Responder: from 1.0, up to and including 1.5
Published 2019-07-28. Last modified 2026-06-17.