CVE-2023-33476
 
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-05-22 CVE Reserved
- 2023-06-02 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-11-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/06/msg00027.html | Mailing List | |
https://sourceforge.net/projects/minidlna | Product |
URL | Date | SRC |
---|---|---|
https://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html | 2024-08-02 |
URL | Date | SRC |
---|---|---|
https://sourceforge.net/p/minidlna/git/ci/9bd58553fae5aef3e6dd22f51642d2c851225aec | 2023-11-25 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202311-12 | 2023-11-25 | |
https://www.debian.org/security/2023/dsa-5434 | 2023-11-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Readymedia Project Search vendor "Readymedia Project" | Readymedia Search vendor "Readymedia Project" for product "Readymedia" | >= 1.1.15 <= 1.3.2 Search vendor "Readymedia Project" for product "Readymedia" and version " >= 1.1.15 <= 1.3.2" | - |
Affected
|