Bug#703281: rygel security issue

2013-04-29 Thread n8fer
Ok I got a full analyse of the behaviour: (Tested with debian wheezy rc2. each test was performed on a fresh installation) how to activate rygel after triggering the bug: starting and closing rygel for the first time (without changing the checkbox) this triggers the bug. full start and stop

Bug#703281: rygel security issue

2013-04-28 Thread n8fer
Can partially confirm, but all that this does is setting the checkmark in the UI. While this is confusing, it doesn't actually launch Rygel or create the symlink necessary to autostart Rygel; no media is shared by accident just by launching rygel-preferences twice. I have spend some time

Bug#703281: rygel security issue

2013-04-22 Thread Andreas Henriksson
Hello Michael Karcher! On Sun, Apr 21, 2013 at 02:53:27PM +0200, Michael Karcher wrote: This behaviour is caused by the global (system wide) configuration file /etc/rygel.conf containing upnp-enabled=true. [...] A short-term fix would be to ship with upnp-enabled=false in the global

Bug#703281: rygel security issue

2013-04-21 Thread Michael Karcher
Package: rygel Version: 0.14.3-2 Followup-For: Bug #703281 This behaviour is caused by the global (system wide) configuration file /etc/rygel.conf containing upnp-enabled=true. That file is used as template for the local (user specific) configuration file, which is written when you exit

Bug#703281: rygel security issue

2013-04-20 Thread John Paul Adrian Glaubitz
Since the problem is reproducible only when rygel-preferences is run for the first and second time consecutively (no ~/.config/rygel.conf initially exists), it must be related to the fact that rygel-preferences cannot find an existing configuration file and hence a default setting for the

Bug#703281: rygel security issue

2013-03-18 Thread Andreas Henriksson
On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: [...] When starting rygel preferences a second time (without having changed the preferences) the sharing option is activated. Unreproducible. Therefore everyone starting rygel preferences for once, activates the uPnP

Bug#703281: rygel security issue

2013-03-18 Thread debmail
On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: [...] When starting rygel preferences a second time (without having changed the preferences) the sharing option is activated. Unreproducible. The bug is only reproducible when using rygel the first time. When on a newly

Bug#703281: rygel security issue

2013-03-18 Thread debmail
Package: rygel Version: 0.14.3-2 Severity: important On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: [...] When starting rygel preferences a second time (without having changed the preferences) the sharing option is activated. Unreproducible. The bug is only

Bug#703281: rygel security issue

2013-03-18 Thread mike . a . oliver
On Sunday, March 17, 2013 7:20:01 PM UTC-4, deb...@lavabit.com wrote: Package: rygel Version: 0.14.3-2 Severity: important Dear Maintainer, The current version of rygel which is part of Debian Wheezy contains a possibly security issue: When starting rygel

Bug#703281: rygel security issue

2013-03-17 Thread debmail
Package: rygel Version: 0.14.3-2 Severity: important Dear Maintainer, The current version of rygel which is part of Debian Wheezy contains a possibly security issue: When starting rygel preferences a second time (without having changed the preferences) the sharing option is activated.