PT-2022-17908 · Unknown+3 · Readymedia+3

Gabriel Corona

·

Published

2022-03-06

·

Updated

2024-06-15

·

CVE-2022-26505

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ReadyMedia (formerly MiniDLNA) versions prior to 1.3.1
Description A DNS rebinding issue allows a remote web server to exfiltrate media files.
Recommendations For versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1492
ALT-PU-2024-3412
ALT-PU-2024-4163
CVE-2022-26505
DLA-2973-1
MGASA-2022-0391
OPENSUSE-SU-2022:0079-1
OPENSUSE-SU-2024:11897-1
USN-6398-1

Affected Products

Alt Linux
Linuxmint
Readymedia
Ubuntu