From URL: "I have released new versions of GUPnP. The main "feature" of this release is the implementation of the UDA 2.0 spec addendum from 2020/04/17 which restricts notifications registered with SUBSCRIBE to the subnet of the server. For this reason, a new GSSDP version is required to provide the required information. This is a reaction to CVE-2020-12695 (https://www.callstranger.com/)"
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d60d8b4ff2362c2e130e1096bd769fefaa1a7d32 commit d60d8b4ff2362c2e130e1096bd769fefaa1a7d32 Author: Mart Raudsepp <leio@gentoo.org> AuthorDate: 2020-06-27 12:45:43 +0000 Commit: Mart Raudsepp <leio@gentoo.org> CommitDate: 2020-06-27 12:45:43 +0000 net-libs/gupnp: bump to 1.2.3 Bug: https://bugs.gentoo.org/729306 Package-Manager: Portage-2.3.84, Repoman-2.3.20 Signed-off-by: Mart Raudsepp <leio@gentoo.org> net-libs/gupnp/Manifest | 1 + net-libs/gupnp/gupnp-1.2.3.ebuild | 84 +++++++++++++++++++++++++++++++++++++++ 2 files changed, 85 insertions(+)
Removed gssdp from summary, as as far as I can see, there's nothing vulnerable in there in itself, but gupnp version with mitigations just needs that now as a minimum version to implement the mitigation.
arm64 stable
amd64 stable
ppc64 stable
x86 stable. Maintainer(s), please cleanup. Security, please vote.
GLSA vote: no
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ddc30eee753215e4320afa847198ffa05823579a commit ddc30eee753215e4320afa847198ffa05823579a Author: John Helmert III <jchelmert3@posteo.net> AuthorDate: 2020-07-30 06:40:43 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2020-10-04 14:01:09 +0000 net-libs/gupnp: Security cleanup (drop <1.2.3) Bug: https://bugs.gentoo.org/729306 Package-Manager: Portage-3.0.1, Repoman-2.3.23 Signed-off-by: John Helmert III <jchelmert3@posteo.net> Closes: https://github.com/gentoo/gentoo/pull/16908 Signed-off-by: Sam James <sam@gentoo.org> net-libs/gupnp/Manifest | 2 - net-libs/gupnp/gupnp-1.0.4.ebuild | 73 -------------------------------- net-libs/gupnp/gupnp-1.2.2.ebuild | 88 --------------------------------------- 3 files changed, 163 deletions(-)