First published: Thu Feb 04 2021(Updated: )
It was discovered that ReadyMedia (MiniDLNA) allowed subscription requests with a delivery URL on a different network segment than the fully qualified event- subscription URL. An attacker could use this to hijack smart devices and cause denial of service attacks. (CVE-2020-12695) It was discovered that ReadyMedia (MiniDLNA) allowed remote code execution. A remote attacker could send a malicious UPnP HTTP request to the service using HTTP chunked encoding and cause a denial of service. (CVE-2020-28926)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/minidlna | <1.2.1+dfsg-2ubuntu0.1 | 1.2.1+dfsg-2ubuntu0.1 |
=20.10 | ||
All of | ||
ubuntu/minidlna | <1.2.1+dfsg-1ubuntu0.20.04.1 | 1.2.1+dfsg-1ubuntu0.20.04.1 |
=20.04 | ||
All of | ||
ubuntu/minidlna | <1.2.1+dfsg-1ubuntu0.18.04.1 | 1.2.1+dfsg-1ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/minidlna | <1.1.5+dfsg-2ubuntu0.1 | 1.1.5+dfsg-2ubuntu0.1 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12695
ReadyMedia (MiniDLNA) version 1.2.1+dfsg-2ubuntu0.1
The severity of this vulnerability is not specified in the advisory.
An attacker can exploit this vulnerability by hijacking smart devices and causing denial of service attacks.
To fix this vulnerability, update ReadyMedia (MiniDLNA) to version 1.2.1+dfsg-2ubuntu0.1 or later.