Bug#699561: djmount: multiple vulnerabilities in libupnp

2013-02-20 Thread Dario Minnucci
Hi Yves, On 02/01/2013 09:29 PM, Yves-Alexis Perez wrote: Package: djmount Severity: grave Tags: security Justification: user security hole libupnp has multiple vulnerabilities in unique_service_name() function. djmount embeds libupnp (which is a bad thing per se, another bug is

Bug#699561: djmount: multiple vulnerabilities in libupnp

2013-02-20 Thread Yves-Alexis Perez
On mer., 2013-02-20 at 19:23 +0100, Dario Minnucci wrote: djmount is always built using --with-external-libupnp and --with-external-talloc arguments to ensure is using libs provided by libtalloc-dev and libupnp-dev debian packages. Thanks, I guess you can just close the bug as false positive

Bug#699561: djmount: multiple vulnerabilities in libupnp

2013-02-01 Thread Yves-Alexis Perez
Package: djmount Severity: grave Tags: security Justification: user security hole libupnp has multiple vulnerabilities in unique_service_name() function. djmount embeds libupnp (which is a bad thing per se, another bug is coming). As djmount is a “client” application I'm not sure it's really