ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.
[
{
"signature_type": "Line",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@9d549098244cca65f0eb8485c3bf745b333cb21f",
"digest": {
"threshold": 0.9,
"line_hashes": [
"50044268764040235103844777223574777799",
"90014531829342240102963853784903825275",
"270695055198022545018950781330555653849",
"101054709125482475682194283404708434615",
"32847315930515115560080164771925388721",
"185443545178025434431264567206647709814",
"136836019837514856879836303090612096241",
"54696133971889332352531392023759677600",
"267448394938761460263077577841990073102",
"81832169926302842594005233722085441487"
]
},
"target": {
"file": "slirp.c"
},
"id": "CVE-2020-28926-1d8ebe3f",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@9d549098244cca65f0eb8485c3bf745b333cb21f",
"digest": {
"threshold": 0.9,
"line_hashes": [
"36612736620355711450665220823640735506",
"136752409856040173183805175396516239884",
"33172293128964601805615205060723814787",
"132081564672955823382980737335455193695",
"137918643295637661236595304114371507062",
"113957087037458593603596628856544728591",
"314504761820656147127371131135078930629"
]
},
"target": {
"file": "slirp.h"
},
"id": "CVE-2020-28926-1f99d7cc",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@9d549098244cca65f0eb8485c3bf745b333cb21f",
"digest": {
"threshold": 0.9,
"line_hashes": [
"174392152832456967490641840846693393641",
"250265143545326910119964963619239666298",
"45238775968788450930331492529435833004",
"179415394475721069611822640264334111648"
]
},
"target": {
"file": "libslirp.h"
},
"id": "CVE-2020-28926-49155bb7",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@9d549098244cca65f0eb8485c3bf745b333cb21f",
"digest": {
"function_hash": "251248990906980338242816762622293163031",
"length": 871.0
},
"target": {
"file": "slirp.c",
"function": "slirp_init"
},
"id": "CVE-2020-28926-7ca433d3",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@9d549098244cca65f0eb8485c3bf745b333cb21f",
"digest": {
"function_hash": "148183029650464572631720857580188979260",
"length": 261.0
},
"target": {
"file": "slirp.c",
"function": "slirp_cleanup"
},
"id": "CVE-2020-28926-968ab662",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@9d549098244cca65f0eb8485c3bf745b333cb21f",
"digest": {
"function_hash": "99674389285701604325357461887975994199",
"length": 3674.0
},
"target": {
"file": "bootp.c",
"function": "bootp_reply"
},
"id": "CVE-2020-28926-bf403a70",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"source": "https://gitlab.freedesktop.org/slirp/libslirp@9d549098244cca65f0eb8485c3bf745b333cb21f",
"digest": {
"threshold": 0.9,
"line_hashes": [
"25542412791554655754760134093349985171",
"278970638079157636054660238396656712120",
"20174240718228506943090766661649511852",
"103686656800341122519890748507829173122"
]
},
"target": {
"file": "bootp.c"
},
"id": "CVE-2020-28926-f6fc5dc0",
"deprecated": false,
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-28926.json"