Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 761882 - media-video/ushare: depends on vulnerable net-libs/libupnp
Summary: media-video/ushare: depends on vulnerable net-libs/libupnp
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Ben Kohler
URL:
Whiteboard:
Keywords:
Depends on: 767460
Blocks: CVE-2020-13848
  Show dependency tree
 
Reported: 2020-12-27 07:56 UTC by John Helmert III
Modified: 2021-02-03 13:38 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-12-27 07:56:14 UTC
ushare depends on libupnp 1.6, and this is blocking cleanup of vulnerable versions of libupnp (<1.14.0). Can anything be done about this?

https://github.com/gentoo/gentoo/pull/18825
https://qa-reports.gentoo.org/output/gentoo-ci/874a5fc10e/output.html#media-video/ushare
Comment 1 Larry the Git Cow gentoo-dev 2020-12-28 14:47:18 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2fe38cf52c19aff76ce9ef3073184109d639356c

commit 2fe38cf52c19aff76ce9ef3073184109d639356c
Author:     Ben Kohler <bkohler@gentoo.org>
AuthorDate: 2020-12-28 14:33:18 +0000
Commit:     Ben Kohler <bkohler@gentoo.org>
CommitDate: 2020-12-28 14:47:08 +0000

    media-video/ushare: new upstream & snapshot
    
    Also move to EAPI=7, GLEP81 user, some patch cleanup
    
    Bug: https://bugs.gentoo.org/761882
    
    Package-Manager: Portage-3.0.12, Repoman-3.0.2
    Signed-off-by: Ben Kohler <bkohler@gentoo.org>

 media-video/ushare/Manifest                     |  1 +
 media-video/ushare/ushare-1.1a_p20200824.ebuild | 67 +++++++++++++++++++++++++
 2 files changed, 68 insertions(+)
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-02-03 00:00:29 UTC
Can cleanup now, please do! \o/
Comment 3 Larry the Git Cow gentoo-dev 2021-02-03 13:38:37 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b95bb9d436526ffa17b44909a659e94477e5bd31

commit b95bb9d436526ffa17b44909a659e94477e5bd31
Author:     Ben Kohler <bkohler@gentoo.org>
AuthorDate: 2021-02-03 13:38:14 +0000
Commit:     Ben Kohler <bkohler@gentoo.org>
CommitDate: 2021-02-03 13:38:14 +0000

    media-video/ushare: drop old
    
    Closes: https://bugs.gentoo.org/761882
    Package-Manager: Portage-3.0.14, Repoman-3.0.2
    Signed-off-by: Ben Kohler <bkohler@gentoo.org>

 media-video/ushare/Manifest                        |   1 -
 .../files/04_all_ushare_upnp_build_fix.patch       | 156 ---------------------
 .../ushare/files/05_all_missing_headers.patch      |  59 --------
 .../files/06_all_ushare_disable_sysconf.patch      |  20 ---
 media-video/ushare/files/08_all_gcc5.patch         |  45 ------
 media-video/ushare/files/ushare.init.d             |  78 -----------
 media-video/ushare/ushare-1.1a-r9.ebuild           |  62 --------
 7 files changed, 421 deletions(-)