A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Readymedia | Readymedia_project | * | 1.3.1 (excluding) |
Minidlna | Ubuntu | bionic | * |
Minidlna | Ubuntu | esm-apps/bionic | * |
Minidlna | Ubuntu | esm-apps/xenial | * |
Minidlna | Ubuntu | focal | * |
Minidlna | Ubuntu | jammy | * |
Minidlna | Ubuntu | kinetic | * |
Minidlna | Ubuntu | upstream | * |
Minidlna | Ubuntu | xenial | * |