VDB
GCVE-110-MAGEIA-2020-483
GCVE-110-MAGEIA-2020-483
Advisory Published
It was discovered that minidlna does not forbid the acceptance of a
subscription request with a delivery URL on a different network segment than
the fully qualified event-subscription URL, aka the CallStranger issue
(CVE-2020-12695).
Minidlna before versions 1.3.0 allows remote code execution. Sending a
malicious UPnP HTTP request to the miniDLNA service using HTTP chunked
encoding can lead to a signedness bug resulting in a buffer overflow in calls
to memcpy/memmove (CVE-2020-28926).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | minidlna | 0 (affected), 1.2.1-3.1.mga7 (unaffected) | — |
Aliases
Browse GCVE Records
74,496 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.