CVE-2020-28926
CRITICALReadyMedia < 1.3.0 - Remote Code Execution via UPnP HTTP Chunked Encoding
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-28926. PoCs published by lorsanta.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2020-28926, a heap corruption vulnerability in MiniDLNA 1.2.1. The exploit leverages malformed chunked encoding in HTTP requests to trigger either an infinite loop or a SIGSEGV via memmove().
Description
ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.
Exploits (1)
This repository contains a functional exploit for CVE-2020-28926, a heap corruption vulnerability in MiniDLNA 1.2.1. The exploit leverages malformed chunked encoding in HTTP requests to trigger either an infinite loop or a SIGSEGV via memmove().
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H