Does 1.31.1.6733-bc0674160 Fix the Remote Code execution vulnerability that Lastpass's Developer saw

Server Version#: 1.31.1.6733-bc0674160
Player Version#:

The story I saw implied Plex was responsible, saying that the LastPass developer also used it. If you have a link with more details, please share it. I’m not ready to crucify Plex yet.

This is all I’m seeing:

Not sure where Plex is involved here but forwarded to security team.

I think at this point it’s assumed he was hacked via his Plex server but there aren’t many details:

Nothing shown to support that.

Please be very careful with assertions and assumptions. ā€œASSUMEā€ is dangerous.

Makes an ASS of U and ME :slight_smile:

From ā€œHome Computerā€ to ā€œPlex Serverā€ is a bigger leap than I would take at this point.

This is where I first saw plex mentioned by name, but I’m not sleuthing this story…

I tried to point out buffer overflows in the past, and was not responded to.

I remember this.

Interestingly, ArsTechnica heard from sources that the engineer’s computer was hacked through a vulnerability found in the Plex media platform. Twelve days after the LastPass attack, Plex confirmed that it had also suffered an attack that resulted in 15 million users’ passwords being stolen.

If you all remember correctly, that’s when operations

  1. Made operations changes in the code and secured the vulnerability
  2. Invalidated EVERYONE’s passwords
  3. Made us all reclaim our servers again
  4. Log in all our devices again

Is Plex the attack vector or another victim?

Let’s please be objective and not emotionally reactive.

As mentioned in the duplicate thread on this topic though, the question is, is this a new event or the old one ?

I agree that this type of ā€˜news’ item (quoted below) needs to be approached with a high degree of scepticism especially as the source asked to be kept anonymous.

ArsTechnica heard from sources that the engineer’s computer was hacked through a vulnerability found in the Plex media platform.

Well, then how about an official response then about my email sent to security@plex.tv on 1/29/2022 about buffer overflows.

Might have less fuel for the boat if you can higher a well qualified security team.

Were you responding to me? So, you didn’t get my email sent to security@plex.tv, or you were unable to send me mail? what? I don’t know if you’re comment on my thread hijacking @BigWheel , or… People can have more then one email address, right?

I have nothing to do with the security email box. I am only giving everyone in this topic a link to the information we have about the LP thing.

Can I pm you a message ID from my mail and you can contact security on my behalf for a response on why I was never contacted in my four mails to your company?

I can’t do anything about speeding up a response from them. I imagine they likely have received hundreds of emails about it and might just be taking a while to respond.

Date: Sat, 29 Jan 2022

Thats when I sent in my ignored bug bounty

You are welcome to message me but I make no promises I will be able to facilitate speeding up a response

a response from more then a year ago? ping @elan

@Gloppie I pinged some folks who said they would look into it.

I’ve still not received a response.