DNS rebinding in ReadyMedia (formerly MiniDLNA) - CVE-2022-26505

 

DNS rebinding in ReadyMedia (formerly MiniDLNA) - CVE-2022-26505

Published: March 7, 2022


Vulnerability identifier: #VU61051
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26505
CWE-ID: CWE-350
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DNS  rebinding attacks.

The vulnerability exists due to the application is prone to DNS rebinding attacks. A remote attacker can trick the victim browser into triggering arbitrary UPnP requests on the local DLNA server and obtain results of such actions, including the ability to read shared files.


Affected software

ReadyMedia (formerly MiniDLNA)
Gentoo Linux
Ubuntu
minidlna (Ubuntu package)
net-misc/minidlna

How to mitigate CVE-2022-26505

Install updates from vendor's website.

ReadyMedia (formerly MiniDLNA) - update to 1.3.1
minidlna (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.1+dfsg-1ubuntu0.20.04.2, 1.3.0+dfsg-2.1ubuntu0.1, 1.3.0+dfsg-2.2ubuntu0.1
net-misc/minidlna - update to 1.3.3

External References

Related Security Bulletins