DNS rebinding in ReadyMedia (formerly MiniDLNA) - CVE-2022-26505
Published: March 7, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform DNS rebinding attacks.
The vulnerability exists due to the application is prone to DNS rebinding attacks. A remote attacker can trick the victim browser into triggering arbitrary UPnP requests on the local DLNA server and obtain results of such actions, including the ability to read shared files.
Affected software
Gentoo Linux
Ubuntu
minidlna (Ubuntu package)
net-misc/minidlna
How to mitigate CVE-2022-26505
minidlna (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.1+dfsg-1ubuntu0.20.04.2, 1.3.0+dfsg-2.1ubuntu0.1, 1.3.0+dfsg-2.2ubuntu0.1
net-misc/minidlna - update to 1.3.3