Also upgrade to a version of Bitcoin Core at least 0.10.3 or 0.11.1 . These versions upgrade the library to a non-vulnerable version, as well as disable UPnP by default to prevent this problem in the future.

Details

Version before 1.9.20151008 of the miniupnpc library are vulnerable to a buffer overflow in the XML parser during initial network discovery. The vulnerable code triggers at startup of Bitcoin Core if UPnP is enabled.

Details of the vulnerability can be found here: http://talosintel.com/reports/TALOS-2015-0035/

It has been verified that the vulnerability can be used to crash the application at startup by running a malicious UPnP server on the local network.

To have more connectable nodes, the Bitcoin Core executables distributed by bitcoin.org include the miniupnpc library and have always had UPnP functionality enabled by default, to forward the P2P port.

This applies to the distributed executables only, not those built from source or from distribution provided packages. Self-built executables have UPnP disabled by default, unless --enable-upnp-default was provided to the configure script.

Releases starting from 0.10.3 and 0.11.1, and the upcoming 0.12.0 will still ship with (a patched version) of the library, but no longer enable the functionality by default.