Unknown · Readymedia · CVE-2023-33476
**Name of the Vulnerable Software and Affected Versions**
ReadyMedia (MiniDLNA) versions 1.1.15 through 1.3.2
**Description**
The issue is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-bounds read/write. The vulnerability can be exploited for remote code execution.
**Recommendations**
For ReadyMedia (MiniDLNA) versions 1.1.15 through 1.3.2, update to a version that fixes the buffer overflow issue. As a temporary workaround, consider restricting access to HTTP requests using chunked transport encoding until a patch is available.