Out-of-bounds write in ReadyMedia (formerly MiniDLNA) - CVE-2023-33476
Published: June 22, 2023 / Updated: June 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when handling HTTP requests using chunked transport encoding. A remote attacker can send a specially crafted HTTP request to the server, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
Debian Linux
Gentoo Linux
Ubuntu
minidlna (Ubuntu package)
minidlna (Debian package)
net-misc/minidlna
How to mitigate CVE-2023-33476
minidlna (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.1+dfsg-1ubuntu0.20.04.2, 1.3.0+dfsg-2.1ubuntu0.1, 1.3.0+dfsg-2.2ubuntu0.1
minidlna (Debian package) - addressed in versions 1.3.0+dfsg-2.2+deb12u1, 1.3.0+dfsg-2+deb11u2
net-misc/minidlna - update to 1.3.3
Links to Public Exploits and PoC-codes
External References
- https://sourceforge.net/projects/minidlna/
- https://sourceforge.net/p/minidlna/git/ci/9bd58553fae5aef3e6dd22f51642d2c851225aec/
- https://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00027.html
- https://www.debian.org/security/2023/dsa-5434