Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-33476
Description:ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2023.3465   1.3.6.1.4.1.25623.1.1.10.2023.0224   1.3.6.1.4.1.25623.1.0.856040   1.3.6.1.4.1.25623.1.1.1.1.2023.5434  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-33476
Debian Security Information: DSA-5434 (Google Search)
https://www.debian.org/security/2023/dsa-5434
https://security.gentoo.org/glsa/202311-12
https://blog.coffinsec.com/0day/2023/05/31/minidlna-heap-overflow-rca.html
https://sourceforge.net/p/minidlna/git/ci/9bd58553fae5aef3e6dd22f51642d2c851225aec/
https://sourceforge.net/projects/minidlna/
https://lists.debian.org/debian-lts-announce/2023/06/msg00027.html




© 1998-2025 E-Soft Inc. All rights reserved.