Skip to content

Drop UpnpInit#214

Merged
hzeller merged 1 commit into
hzeller:masterfrom
ffontaine:master
Jan 14, 2021
Merged

Drop UpnpInit#214
hzeller merged 1 commit into
hzeller:masterfrom
ffontaine:master

Conversation

@ffontaine
Copy link
Copy Markdown
Contributor

@ffontaine ffontaine commented Aug 21, 2020

UpnpInit has been dropped from libupnp 1.14.x as it can't be fixed against CallStranger a.k.a. CVE-2020-12695 so replace it by UpnpInit2 which is available since version 1.6.7 and pupnp/pupnp@2bcbdff

Signed-off-by: Fabrice Fontaine fontaine.fabrice@gmail.com

@mill1000
Copy link
Copy Markdown
Contributor

How far back is UpnpInit2 available? I think there are a number of users who still build against libupnp 1.6.

@ffontaine
Copy link
Copy Markdown
Contributor Author

ffontaine commented Aug 21, 2020

UpnpInit2 is available since version 1.6.7 and pupnp/pupnp@2bcbdff but more importantly without this change (and the use of pupnp version 1.14.x), users are not protected against CallStranger which has a High CVE score: https://nvd.nist.gov/vuln/detail/CVE-2020-12695.

Copy link
Copy Markdown
Owner

@hzeller hzeller left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing the CVE vulnerability.

The change of the ip-address flag name is missing in the manpage. Other than that, LGTM.

Comment thread dist-scripts/debian/gmediarender.1 Outdated
UpnpInit has been dropped from libupnp 1.14.x as it can't be fixed
against CallStranger a.k.a. CVE-2020-12695 so replace it by UpnpInit2
which is available since version 1.6.7 and
pupnp/pupnp@2bcbdff

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
ardumont added a commit to ardumont/nixpkgs that referenced this pull request Oct 6, 2020
@whyman
Copy link
Copy Markdown

whyman commented Jan 14, 2021

Can we get this merged? Most distros are dropping libupnp <0.14.0

@hzeller hzeller merged commit 7cd7452 into hzeller:master Jan 14, 2021
hzeller added a commit that referenced this pull request Jan 14, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants