openSUSE-SU-2022:0079-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:0079-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2022:0079-1
Related
Published
2022-03-10T23:02:00Z
Modified
2022-03-10T23:02:00Z
Summary
Security update for minidlna
Details

This update for minidlna fixes the following issues:

minidlna was updated to version 1.3.1 (boo#1196814)

  • Fixed a potential crash in SSDP request parsing.
  • Fixed a configure script failure on some platforms.
  • Protect against DNS rebinding attacks. (CVE-2022-26505)
  • Fix an socket leakage issue on some platforms.
  • Minor bug fixes.

  • add 'su minidlna minidlna' to the logrotate config

  • Added hardening to systemd service(s) (boo#1181400).
  • Use sysusers macros to create minidlna user
  • Don't hardrequire logrotate, we don't write log files anymore
References

Affected packages

SUSE:Package Hub 15 SP3 / minidlna

Package

Name
minidlna
Purl
pkg:rpm/suse/minidlna&distro=SUSE%20Package%20Hub%2015%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.1-bp153.2.3.1

Ecosystem specific

{
    "binaries": [
        {
            "minidlna": "1.3.1-bp153.2.3.1"
        }
    ]
}

openSUSE:Leap 15.3 / minidlna

Package

Name
minidlna
Purl
pkg:rpm/opensuse/minidlna&distro=openSUSE%20Leap%2015.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.1-bp153.2.3.1

Ecosystem specific

{
    "binaries": [
        {
            "minidlna": "1.3.1-bp153.2.3.1"
        }
    ]
}