Debian 10225 Published by

A minidlna security update has been released for Debian GNU/Linux 8 Extended LTS to validate HTTP requests to protect against DNS rebinding.



ELA-591-1 minidlna security update

Package minidlna
Version 1.1.2+dfsg-1.1+deb8u1
Related CVEs CVE-2022-26505

Validate HTTP requests to protect against DNS rebinding, thus forbid a remote web server to exfiltrate media files.

For Debian 8 jessie, these problems have been fixed in version 1.1.2+dfsg-1.1+deb8u1.

We recommend that you upgrade your minidlna packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-591-1 minidlna security update