
Cloud Vulnerability DB
A community-led vulnerabilities database
A stack-buffer-overflow vulnerability was discovered in ReadyMedia (formerly known as MiniDLNA) version 1.3.3. The vulnerability allows attackers to cause a denial of service via the SendContainer() function in tivo_commands.c. The issue was reported on March 2, 2024, and was assigned CVE-2023-47430 (SourceForge Bug, NVD).
The vulnerability stems from a lack of proper boundary checks when invoking strcat() on certain variables (order, order2, and myfilter) in the SendContainer() function within tivo_commands.c. The issue has been assigned a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L. The vulnerability is classified as CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (NVD).
When successfully exploited, this vulnerability can lead to a denial of service condition in the affected ReadyMedia/MiniDLNA service. The attack can be triggered remotely, requiring no authentication or user interaction (NVD).
The vulnerability can be triggered by sending specially crafted HTTP requests to the server on port 8200. Example exploit paths include using the QueryContainer command with excessive Filter or SortOrder parameters (SourceForge Bug).
As of the current date, there is no official patch available for this vulnerability. Users running ReadyMedia/MiniDLNA v1.3.3 with TiVo support enabled are affected. The vulnerability can be reproduced when the server is configured with enable_tivo=yes in the configuration file (SourceForge Bug).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."