Описание
Security update for minidlna
This update for minidlna fixes the following issues:
minidlna was updated to version 1.3.0 (boo#1179447)
- Fixed some build warnings when building with musl.
- Use $USER instead of $LOGNAME for the default friendly name.
- Fixed build with GCC 10
- Fixed some warnings from newer compilers
- Disallow negative HTTP chunk lengths. [CVE-2020-28926]
- Validate SUBSCRIBE callback URL. [CVE-2020-12695]
- Fixed spurious warnings with ogg coverart
- Fixed an issue with VLC where browse results would be truncated.
- Fixed bookmarks on Samsung Q series
- Added DSD file support.
- Fixed potential stack smash vulnerability in getsyshwaddr on macOS.
- Will now reload the log file on SIGHUP.
- Worked around bad SearchCriteria from the Control4 Android app.
- Increased max supported network addresses to 8.
- Added forced alphasort capability.
- Added episode season and number metadata support.
- Enabled subtitles by default for unknown DLNA clients, and add enable_subtitles config option.
- Fixed discovery when connected to certain WiFi routers.
- Added FreeBSD kqueue support.
- Added the ability to set the group to run as.
Список пакетов
openSUSE Leap 15.2
minidlna-1.3.0-lp152.4.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:2160-1
- SUSE Security Ratings
- SUSE Bug 1179447
- SUSE CVE CVE-2020-12695 page
- SUSE CVE CVE-2020-28926 page
Описание
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
Затронутые продукты
openSUSE Leap 15.2:minidlna-1.3.0-lp152.4.3.1
Ссылки
- CVE-2020-12695
- SUSE Bug 1172700
- SUSE Bug 1179447
Описание
ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.
Затронутые продукты
openSUSE Leap 15.2:minidlna-1.3.0-lp152.4.3.1
Ссылки
- CVE-2020-28926
- SUSE Bug 1179447