| Summary: | minidlna new security issue CVE-2023-33476 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, geiger.david68210, herman.viaene, mageia, nicolas.salguero, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | minidlna-1.3.2-2.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2023-06-22 20:44:26 CEST
David Walser
2023-06-22 20:44:46 CEST
Status comment:
(none) =>
Fixed upstream in 1.3.3 Not obvious who might do this, so assigning it globally. CC'ing NicolasS who put up the current version. CC:
(none) =>
nicolas.salguero Done for both mga8 and cauldron! CC:
(none) =>
geiger.david68210 minidlna-1.3.3-1.mga8 from minidlna-1.3.3-1.mga8.src.rpm Freeze move requested for Cauldron I assume. Fixed for cauldron now! Assigning to QA. Status comment:
Fixed upstream in 1.3.3 =>
(none)
PC LX
2023-06-28 11:53:16 CEST
CC:
(none) =>
mageia MGA8-64 MATE on Acer Aspire 5253 No installation issues. Ref bug 30115 edited /etc/minidlna.conf the media_dir and network_interface. # systemctl restart minidlna.service [root@mach7 ~]# systemctl status minidlna.service ● minidlna.service - MiniDLNA is a DLNA/UPnP-AV server software Loaded: loaded (/usr/lib/systemd/system/minidlna.service; disabled; vendor preset: disabled) Active: active (running) since Thu 2023-06-29 16:04:30 CEST; 3s ago Main PID: 21859 (minidlnad) Tasks: 2 (limit: 4364) Memory: 4.0M CPU: 97ms CGroup: /system.slice/minidlna.service └─21859 /usr/sbin/minidlnad -S Jun 29 16:04:30 mach7.hviaene.thuis systemd[1]: Started MiniDLNA is a DLNA/UPnP-AV server software. Jun 29 16:04:32 mach7.hviaene.thuis minidlnad[21859]: [2023/06/29 16:04:32] minidlna.c:669: error: Media directory "/h> Jun 29 16:04:32 mach7.hviaene.thuis minidlnad[21859]: minidlna.c:1134: warn: Starting MiniDLNA version 1.3.3. Jun 29 16:04:32 mach7.hviaene.thuis minidlnad[21859]: minidlna.c:1182: warn: HTTP listening on port 8200 Then tried to access it from VLC, at first without success, googling found out I have to open on the firewall 8200/tcp and 1900/udp. Then I see in VLV the minidlna server and the media_dir given above, but I cann't get it to display the wav files in it. I've never got the hang of using playlist, so I give this minidlna the OK, not withholding it for VLC-issues. CC:
(none) =>
herman.viaene Validating. Keywords:
(none) =>
validated_update
Dave Hodgins
2023-07-06 23:12:34 CEST
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2023-0224.html Resolution:
(none) =>
FIXED |