VDB
GCVE-VVD-MAGEIA-2020-483
GCVE-VVD-MAGEIA-2020-483
Advisory Published
It was discovered that minidlna does not forbid the acceptance of a
subscription request with a delivery URL on a different network segment than
the fully qualified event-subscription URL, aka the CallStranger issue
(CVE-2020-12695).
Minidlna before versions 1.3.0 allows remote code execution. Sending a
malicious UPnP HTTP request to the miniDLNA service using HTTP chunked
encoding can lead to a signedness bug resulting in a buffer overflow in calls
to memcpy/memmove (CVE-2020-28926).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | minidlna | 0 (affected), 1.2.1-3.1.mga7 (unaffected) | — |
Aliases
Transitive aliases
VVD-GENTOO-2020-727542VVD-MAGEIA-2020-304VVD-GENTOO-2020-729302EUVD-2020-21314OPENSUSE-SU-2024:11050-1CNVD-2022-06535VVD-GENTOO-2020-729306GHSA-wp9w-2vp9-wg66BDU:2021-01774OPENSUSE-SU-2020:2194-1GSD-2020-28926OPENSUSE-SU-2020:2226-1OPENSUSE-SU-2020:2160-1ALSA-2021:1789CNVD-2020-37941VVD-GENTOO-2020-729946BDU:2021-01329GHSA-gvj3-gg8w-3vrmOPENSUSE-SU-2020:2204-1EUVD-2020-4987VVD-CERTCC-2020-339275
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.