Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 729946 - <net-libs/libupnpp-0.19.4: CallStranger vulnerability (CVE-2020-12695)
Summary: <net-libs/libupnpp-0.19.4: CallStranger vulnerability (CVE-2020-12695)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks: CVE-2020-12695
  Show dependency tree
 
Reported: 2020-06-27 20:57 UTC by Sam James
Modified: 2021-08-06 04:00 UTC (History)
1 user (show)

See Also:
Package list:
net-libs/libupnpp-0.19.4 *
Runtime testing required: ---
nattka: sanity-check-


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-27 20:57:26 UTC
From https://www.lesbonscomptes.com/upmpdcli/releases.html:
"libnpupnp: fix vulnerability to CVE-2020-12695 (CallStranger)."
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-27 20:58:14 UTC
Please bump to 0.19.2.
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-20 11:01:02 UTC
Ping. Please let us know if you're unable to patch this right now.
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-12-27 07:51:48 UTC
A few newer versions are in tree now, can we stabilize any of them? The stable version currently depends on a vulnerable libupnp and blocks its cleanup for bug 727170.
Comment 4 NATTkA bot gentoo-dev 2020-12-27 07:53:03 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2020-12-27 16:29:01 UTC Comment hidden (obsolete)
Comment 6 Erik Mackdanz gentoo-dev 2020-12-27 16:39:23 UTC
I've stabilized the newer version that doesn't have problematic dependency.

Sorry this wasn't on my radar at all.  I missed a lot of emails from earlier in the year, and I see that security bugs aren't assigned to the maintainer.
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-12-27 17:22:23 UTC
(In reply to Erik Mackdanz from comment #6)
> I've stabilized the newer version that doesn't have problematic dependency.
> 
> Sorry this wasn't on my radar at all.  I missed a lot of emails from earlier
> in the year, and I see that security bugs aren't assigned to the maintainer.

No worries! In case you missed this too, there's a new way to check these things:

https://packages.gentoo.org/maintainer/stasibear@gentoo.org/security
Comment 8 NATTkA bot gentoo-dev 2020-12-27 17:25:02 UTC Comment hidden (obsolete)
Comment 9 Erik Mackdanz gentoo-dev 2020-12-27 20:58:23 UTC
Super, I've got that bookmarked, thanks.
Comment 10 NATTkA bot gentoo-dev 2021-04-01 20:12:56 UTC
Unable to check for sanity:

> no match for package: net-libs/libupnpp-0.19.4
Comment 11 Larry the Git Cow gentoo-dev 2021-08-03 21:03:28 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c9e63e733a8923dd407353df0c0ad852cf13b5ad

commit c9e63e733a8923dd407353df0c0ad852cf13b5ad
Author:     Erik Mackdanz <stasibear@gentoo.org>
AuthorDate: 2021-08-03 21:03:09 +0000
Commit:     Erik Mackdanz <stasibear@gentoo.org>
CommitDate: 2021-08-03 21:03:09 +0000

    net-libs/libupnpp: bump to 0.21.0
    
    Closes: https://bugs.gentoo.org/729946
    Signed-off-by: Erik Mackdanz <stasibear@gentoo.org>
    Package-Manager: Portage-3.0.20, Repoman-3.0.3

 net-libs/libupnpp/Manifest               |  1 +
 net-libs/libupnpp/libupnpp-0.21.0.ebuild | 18 ++++++++++++++++++
 2 files changed, 19 insertions(+)
Comment 12 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-06 03:59:44 UTC
No, please don't close security bugs with Closes: tags.
Comment 13 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-08-06 04:00:42 UTC
We can noglsa this one anyway though. All done!