CVE-2013-2745

Publication date 4 December 2019

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

Read the notes from the security team

Status

Package Ubuntu Release Status
minidlna 17.04 zesty
Fixed 1.1.2+dfsg-1
16.10 yakkety
Fixed 1.1.2+dfsg-1
16.04 LTS xenial
Fixed 1.1.2+dfsg-1
15.10 wily
Fixed 1.1.2+dfsg-1
15.04 vivid
Fixed 1.1.2+dfsg-1
14.10 utopic
Fixed 1.1.2+dfsg-1
14.04 LTS trusty Not in release
13.10 saucy Ignored end of life
13.04 raring Ignored end of life
12.10 quantal Ignored end of life
12.04 LTS precise Ignored end of life
10.04 LTS lucid Not in release

Notes


seth-arnold

might be fixed by http://sourceforge.net/p/minidlna/git/ci/cd20aa0b244b46e8173a6c83e4af7b8f1e521c58/

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities