USN-4722-1: ReadyMedia (MiniDLNA) vulnerabilities
It was discovered that ReadyMedia (MiniDLNA) allowed subscription requests with a delivery URL on a different network segment than the fully qualified event- subscription URL. An attacker could use this to hijack smart devices and cause denial of service attacks. (CVE-2020-12695) It was discovered that ReadyMedia (MiniDLNA) allowed remote code execution. A remote attacker could send a malicious UPnP HTTP request to the service using HTTP chunked encoding and cause a denial of service. (CVE-2020-28926)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
CVE-2020-12695
What is the affected software?
ReadyMedia (MiniDLNA) version 1.2.1+dfsg-2ubuntu0.1
What is the severity of this vulnerability?
The severity of this vulnerability is not specified in the advisory.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by hijacking smart devices and causing denial of service attacks.
How can I fix this vulnerability?
To fix this vulnerability, update ReadyMedia (MiniDLNA) to version 1.2.1+dfsg-2ubuntu0.1 or later.