Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:2160-1

Опубликовано: 04 дек. 2020
Источник: suse-cvrf

Описание

Security update for minidlna

This update for minidlna fixes the following issues:

minidlna was updated to version 1.3.0 (boo#1179447)

  • Fixed some build warnings when building with musl.
  • Use $USER instead of $LOGNAME for the default friendly name.
  • Fixed build with GCC 10
  • Fixed some warnings from newer compilers
  • Disallow negative HTTP chunk lengths. [CVE-2020-28926]
  • Validate SUBSCRIBE callback URL. [CVE-2020-12695]
  • Fixed spurious warnings with ogg coverart
  • Fixed an issue with VLC where browse results would be truncated.
  • Fixed bookmarks on Samsung Q series
  • Added DSD file support.
  • Fixed potential stack smash vulnerability in getsyshwaddr on macOS.
  • Will now reload the log file on SIGHUP.
  • Worked around bad SearchCriteria from the Control4 Android app.
  • Increased max supported network addresses to 8.
  • Added forced alphasort capability.
  • Added episode season and number metadata support.
  • Enabled subtitles by default for unknown DLNA clients, and add enable_subtitles config option.
  • Fixed discovery when connected to certain WiFi routers.
  • Added FreeBSD kqueue support.
  • Added the ability to set the group to run as.

Список пакетов

openSUSE Leap 15.2
minidlna-1.3.0-lp152.4.3.1

Описание

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.


Затронутые продукты
openSUSE Leap 15.2:minidlna-1.3.0-lp152.4.3.1

Ссылки

Описание

ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.


Затронутые продукты
openSUSE Leap 15.2:minidlna-1.3.0-lp152.4.3.1

Ссылки
Уязвимость openSUSE-SU-2020:2160-1