Menu

#71 CallStranger a.k.a. CVE-2020-12695

v1.0 (example)
open
nobody
security (1)
9
2021-03-07
2020-09-06
No

minidlna is affected by CallStranger a.k.a. CVE-2020-12695 because it uses a very old version of miniupnpd source code which does not embed the checkCallbackURL function. This function has been added to miniupnpd in 2011/06/27. It must be used in ProcessHTTPSubscribe_upnphttp to check that the callback URL is on the same IP as the request, and not on the internet.

I checked that minidlna in version 1.2.1 was affected by this vulnerability thanks to https://github.com/yunuscadirci/CallStranger

Discussion


Log in to post a comment.