VDB

GCVE-VVD-MAGEIA-2020-483

GCVE-VVD-MAGEIA-2020-483
Advisory Published
Vulnetix · Advisory published December 31, 2020
It was discovered that minidlna does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue (CVE-2020-12695). Minidlna before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove (CVE-2020-28926).

Affected Products

VendorProductVersionsPlatforms
Mageiaminidlna0 (affected), 1.2.1-3.1.mga7 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›