VDB

CVE-2023-33476

CVE-2023-33476 PUBLISHED CVSS 9.300000190734863 CRITICAL

ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write.

EPSS 0.73% · 73.0th percentile

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.73%
73.0th percentile

Affected Products

VendorProductVersions
readymedia_projectreadymedia1.1.15, 1.1.15
n/an/a*, n/a

Timeline

  • Jun 2, 2023 CVE Published
  • Jun 2, 2023 PoC Published
  • Jun 3, 2023 EPSS Score
  • Jun 7, 2023 PoC Published
  • Jun 20, 2023 PoC Published
  • Jun 20, 2023 PoC Published
  • Jun 20, 2023 PoC Published
  • Jun 20, 2023 PoC Published
  • Jun 21, 2023 PoC Published
  • Jun 24, 2023 PoC Published
  • Jun 24, 2023 PoC Published
  • Jun 27, 2023 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›