While Rhythmbox does indeed open a port when started, the user needs to
start it before the port becomes available. This is no different than
opening a Bittorrent client application, or some other application that
opens ports.

That being said, perhaps the plugin should be disabled by default.

Thanks!

** Changed in: rhythmbox (Ubuntu)
       Status: New => Confirmed

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to rhythmbox in Ubuntu.
https://bugs.launchpad.net/bugs/1771196

Title:
   daap plugin opens port by default

Status in rhythmbox package in Ubuntu:
  Confirmed

Bug description:
  In a default installation, the daap plugin is enabled, and listens to
  port 3689 (daap).

  tcp        0      0 *:daap                  *:*
  LISTEN      guest-43a0me 72019       -

  Ubuntu has a "no open ports by default" policy.[1][2]

  [1] https://bugs.launchpad.net/ubuntu/+source/banshee/+bug/753986
  [2] https://wiki.ubuntu.com/SecurityTeam/Policies#No_Open_Ports

  Please resolve this e.g. by updating rhythmbox not to listen on a port
  by default, or documenting rhythmbox as an exception to the security
  policy.

  ---

  Ubuntu 16.04.4 LTS
  rhythmbox 3.3-1ubuntu7

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rhythmbox/+bug/1771196/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to