Summary
The remote host is missing an update to gupnp
announced via advisory FEDORA-2009-5865.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update gupnp' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-5865
Insight
New upstream release that fixes a bug where the gupnp stack crashes when passed empty content.
ChangeLog: http://git.gupnp.org/cgit.cgi?url=gupnp/tree/NEWS&id=ce714a6700ce03953a2886a66ec57db59205f4e6
Bug report: http://bugzilla.openedhand.com/show_bug.cgi?id=1604
Other bugs fixed here.
- bug#1570: gupnp doesn't set the pkgconfig lib dir correctly in 64 bit env.
- bug#1574: Avoid using asserts.
- bug#1592: gupnp_device_info_get_icon_url() does not return the closest match.
- bug#1604: Crash on action without any content.
ChangeLog:
* Wed Jun 3 2009 Peter Robinson 0.12.8-1
- New upstream release
Severity
Classification
-
CVE CVE-2009-2174 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities