ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade minidlna | Jun 23, 2023 | Jun 2, 2023 |
| Gentoo Linux | — | Upgrade net-misc/minidlna. | Nov 27, 2023 | Jun 2, 2023 |
| Suse | — | Upgrade minidlna | Apr 1, 2024 | Jun 2, 2023 |
| Ubuntu | — | Upgrade minidlna (Ubuntu Pro)Upgrade minidlna | Sep 28, 2023 | Jun 2, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub