
CVE-2024-51442 분석 및 예제 구성 파일
CVE-2024-51442는 minidlna/Readyshare 버전 <= 1.3.3의 명령 주입 취약점입니다. 이 취약점은 minidlna.conf에서 사용되는 특수하게 조작된 db_dir 매개변수로 minidlnad를 실행하여 악용할 수 있습니다.
이 취약점은 check_db 함수의 rescan 기능과
minidlna.c
rescan:
CLEARFLAG(RESCAN_MASK);
if (ret < 0)
DPRINTF(E_WARN, L_GENERAL, "Creating new database at %s/files.db\n", db_path);
else if (ret == 1)
DPRINTF(E_WARN, L_GENERAL, "New media_dir detected; rebuilding...\n");
else if (ret == 2)
DPRINTF(E_WARN, L_GENERAL, "Removed media_dir detected; rebuilding...\n");
else
DPRINTF(E_WARN, L_GENERAL, "Database version mismatch (%d => %d); need to recreate...\n",
ret, DB_VERSION);
sqlite3_close(db);
snprintf(cmd, sizeof(cmd), "rm -rf %s/files.db %s/art_cache", db_path, db_path);
if (system(cmd) != 0)
DPRINTF(E_FATAL, L_GENERAL, "Failed to clean old file cache! Exiting...\n");
그리고 -R이 선택적 명령줄 매개변수로 전달될 때 존재합니다:
minidlna.c
case 'R':
snprintf(buf, sizeof(buf), "rm -rf %s/files.db %s/art_cache", db_path, db_path);
if (system(buf) != 0)
DPRINTF(E_FATAL, L_GENERAL, "Failed to clean old file cache %s. EXITING\n", db_path);
break;
위 코드는 db_path를 형식 문자열의 매개변수로 사용하여 "rm -rf %s/files.db %s/art_cache를 실행합니다. db_path는 options.c의 코드에 의해 처리될 때 구성 파일에서 가져옵니다.
이 취약점은 이 저장소의 예제 minidlna.conf를 구성 파일로 사용하여 악용할 수 있습니다. 이는 개념 증명으로 xdg-open을 사용하여 파일 시스템 창을 엽니다.
minidlnad -d -f minidlna.conf