Security Advisory

CVE-2020-28926

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-11-30 17:09:40
Last updated 2024-08-04 16:40:59
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.