First published: Sun Mar 06 2022(Updated: )
A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/minidlna | <1.1.5+dfsg-2ubuntu0.1+ | 1.1.5+dfsg-2ubuntu0.1+ |
ubuntu/minidlna | <1.3.3+dfsg-0.1 | 1.3.3+dfsg-0.1 |
ubuntu/minidlna | <1.2.1+dfsg-1ubuntu0.18.04.1+ | 1.2.1+dfsg-1ubuntu0.18.04.1+ |
ubuntu/minidlna | <1.2.1+dfsg-1ubuntu0.20.04.2 | 1.2.1+dfsg-1ubuntu0.20.04.2 |
ubuntu/minidlna | <1.3.0+dfsg-2.1ubuntu0.1 | 1.3.0+dfsg-2.1ubuntu0.1 |
debian/minidlna | 1.2.1+dfsg-2+deb10u3 1.2.1+dfsg-2+deb10u4 1.3.0+dfsg-2+deb11u2 1.3.0+dfsg-2.2+deb12u1 1.3.3+dfsg-0.1 | |
Readymedia Project Readymedia | <1.3.1 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in ReadyMedia is CVE-2022-26505.
CVE-2022-26505 is a DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 that allows a remote web server to exfiltrate media files.
The affected software versions of CVE-2022-26505 include ReadyMedia (formerly MiniDLNA) versions 1.2.1+dfsg-2+deb10u3, 1.2.1+dfsg-2+deb10u4, 1.3.0+dfsg-2+deb11u1, 1.3.0+dfsg-2+deb11u2, 1.3.0+dfsg-2.2+deb12u1, and 1.3.3+dfsg-0.1.
A remote web server can exploit CVE-2022-26505 through a DNS rebinding attack to exfiltrate media files.
Yes, there are remedies available for CVE-2022-26505, including specific package versions provided by Debian and Ubuntu.