A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2022/03/03/1 | third party advisory mailing list |
https://sourceforge.net/p/minidlna/git/ci/c21208508dbc131712281ec5340687e5ae89e940/ | third party advisory patch |
http://www.openwall.com/lists/oss-security/2022/03/06/1 | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2022/04/msg00005.html | third party advisory mailing list |
https://security.gentoo.org/glsa/202311-12 | vendor advisory |