Vulnerability Details CVE-2020-28926
ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.653
EPSS Ranking 98.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-28926
-
cpe:2.3:a:readymedia_project:readymedia:-
-
cpe:2.3:a:readymedia_project:readymedia:1.0.15
-
cpe:2.3:a:readymedia_project:readymedia:1.0.16
-
cpe:2.3:a:readymedia_project:readymedia:1.0.18
-
cpe:2.3:a:readymedia_project:readymedia:1.0.19
-
cpe:2.3:a:readymedia_project:readymedia:1.0.20
-
cpe:2.3:a:readymedia_project:readymedia:1.0.21
-
cpe:2.3:a:readymedia_project:readymedia:1.0.22
-
cpe:2.3:a:readymedia_project:readymedia:1.0.23
-
cpe:2.3:a:readymedia_project:readymedia:1.0.24
-
cpe:2.3:a:readymedia_project:readymedia:1.0.25
-
cpe:2.3:a:readymedia_project:readymedia:1.0.26
-
cpe:2.3:a:readymedia_project:readymedia:1.1.0
-
cpe:2.3:a:readymedia_project:readymedia:1.1.1
-
cpe:2.3:a:readymedia_project:readymedia:1.1.15
-
cpe:2.3:a:readymedia_project:readymedia:1.1.2
-
cpe:2.3:a:readymedia_project:readymedia:1.1.3
-
cpe:2.3:a:readymedia_project:readymedia:1.1.4
-
cpe:2.3:a:readymedia_project:readymedia:1.1.5
-
cpe:2.3:a:readymedia_project:readymedia:1.2.0
-
cpe:2.3:a:readymedia_project:readymedia:1.2.1
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:9.0