CVE-2023-33476
Debian Security Advisory 5434-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write.
It was discovered that ReadyMedia was vulnerable to DNS rebinding attacks. A remote attacker could possibly use this issue to trick the local DLNA server to leak information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. It was discovered that ReadyMedia incorrectly handled certain HTTP requests using chunked transport encoding. A remote attacker could possibly use this issue to cause buffer overflows, resulting in out-of-bounds reads and writes.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-05-22 CVE Reserved
- 2023-06-02 CVE Published
- 2024-05-15 First Exploit
- 2025-01-08 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/06/msg00027.html | Mailing List |
|
https://sourceforge.net/projects/minidlna | Product |
URL | Date | SRC |
---|---|---|
https://github.com/mellow-hype/cve-2023-33476 | 2024-05-15 | |
https://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html | 2025-01-08 |
URL | Date | SRC |
---|---|---|
https://sourceforge.net/p/minidlna/git/ci/9bd58553fae5aef3e6dd22f51642d2c851225aec | 2023-11-25 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202311-12 | 2023-11-25 | |
https://www.debian.org/security/2023/dsa-5434 | 2023-11-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Readymedia Project Search vendor "Readymedia Project" | Readymedia Search vendor "Readymedia Project" for product "Readymedia" | >= 1.1.15 <= 1.3.2 Search vendor "Readymedia Project" for product "Readymedia" and version " >= 1.1.15 <= 1.3.2" | - |
Affected
|