Bug 42030 - libupnp: remote write to local filesystem via vlc (4.1)
libupnp: remote write to local filesystem via vlc (4.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.1
Other Linux
: P4 normal (vote)
: UCS 4.1-3-errata
Assigned To: Arvid Requate
Philipp Hahn
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-08-18 16:02 CEST by Arvid Requate
Modified: 2016-10-20 12:40 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2016-08-18 16:02:27 CEST
Upstream Debian package version 1:1.6.17-1.2+deb7u1 fixes this issue:

* write files via POST (CVE-2016-6255)

Affects server applications. In UCS libupnp is only used by vlc.
Comment 1 Arvid Requate univentionstaff 2016-10-18 15:36:56 CEST
Imported and built in errata4.1-3, no UCS patches.
Package update worked (amd64).

Advisory: libupnp.yaml
Comment 2 Philipp Hahn univentionstaff 2016-10-18 17:31:10 CEST
FIXED: libupnp.yaml → r73344
OK: errata-announce -V --only libupnp.yaml

OK: univention-install -qq libupnp6 libupnp6-dev
OK: zless /usr/share/doc/libupnp6/changelog.Debian.gz
Comment 3 Janek Walkenhorst univentionstaff 2016-10-20 12:40:27 CEST
<http://errata.software-univention.de/ucs/4.1/300.html>