SB2023062263 - Remote code execution in ReadyMedia
Published: June 22, 2023 Updated: June 22, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2023-33476)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when handling HTTP requests using chunked transport encoding. A remote attacker can send a specially crafted HTTP request to the server, trigger an out-of-bounds write and execute arbitrary code on the target system.
Remediation
Install update from vendor's website.
References
- https://sourceforge.net/projects/minidlna/
- https://sourceforge.net/p/minidlna/git/ci/9bd58553fae5aef3e6dd22f51642d2c851225aec/
- https://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00027.html
- https://www.debian.org/security/2023/dsa-5434