From unknown Sat Jun 21 10:22:22 2025 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Mailer: MIME-tools 5.509 (Entity 5.509) Content-Type: text/plain; charset=utf-8 From: bug#47140 <47140@debbugs.gnu.org> To: bug#47140 <47140@debbugs.gnu.org> Subject: Status: libupnp package vulnerable to CVE-2021-28302 Reply-To: bug#47140 <47140@debbugs.gnu.org> Date: Sat, 21 Jun 2025 17:22:22 +0000 retitle 47140 libupnp package vulnerable to CVE-2021-28302 reassign 47140 guix submitter 47140 Mark H Weaver severity 47140 normal tag 47140 security thanks From debbugs-submit-bounces@debbugs.gnu.org Sun Mar 14 17:30:56 2021 Received: (at submit) by debbugs.gnu.org; 14 Mar 2021 21:30:57 +0000 Received: from localhost ([127.0.0.1]:34321 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lLYK8-0002pJ-MR for submit@debbugs.gnu.org; Sun, 14 Mar 2021 17:30:56 -0400 Received: from lists.gnu.org ([209.51.188.17]:38872) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lLYK5-0002p8-RK for submit@debbugs.gnu.org; Sun, 14 Mar 2021 17:30:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:55114) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lLYK5-0001oq-JL for bug-guix@gnu.org; Sun, 14 Mar 2021 17:30:53 -0400 Received: from world.peace.net ([64.112.178.59]:55680) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lLYK2-0000x8-8k for bug-guix@gnu.org; Sun, 14 Mar 2021 17:30:53 -0400 Received: from mhw by world.peace.net with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1lLYJp-0000gu-L9; Sun, 14 Mar 2021 17:30:37 -0400 From: Mark H Weaver To: bug-guix@gnu.org Subject: libupnp package vulnerable to CVE-2021-28302 References: <57dace27aa78c5c193ed803fc0bc05d55a7646c6.camel@zaclys.net> Date: Sun, 14 Mar 2021 17:29:06 -0400 Message-ID: <87lfaps9tu.fsf@netris.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="=-=-=" Received-SPF: pass client-ip=64.112.178.59; envelope-from=mhw@netris.org; helo=world.peace.net X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-Debbugs-Envelope-To: submit Cc: =?utf-8?Q?L=C3=A9o?= Le Bouter X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable I'm forwarding this to bug-guix@gnu.org so that it won't be forgotten. Mark -------------------- Start of forwarded message -------------------- Subject: libupnp package vulnerable to CVE-2021-28302 From: L=C3=A9o Le Bouter To: guix-devel@gnu.org Date: Sat, 13 Mar 2021 02:12:45 +0100 --=-=-= Content-Type: multipart/signed; boundary="==-=-=" --==-=-= Content-Type: text/plain; charset=utf-8 Content-Disposition: inline CVE-2021-28302 12.03.21 16:15 A stack overflow in pupnp 1.16.1 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash. Upstream did not provide a patch yet, see < https://github.com/pupnp/pupnp/issues/249>. I suggest we wait for the patch to be made and then update, to be monitored. --==-=-= Content-Type: application/pgp-signature; name=signature.asc Content-Transfer-Encoding: base64 Content-Description: This is a digitally signed message part LS0tLS1CRUdJTiBQR1AgU0lHTkFUVVJFLS0tLS0KCmlRSXpCQUFCQ2dBZEZpRUVGSXZMaTlnTCt4 YXgzZzZSUmFpeDZHdk5FS1lGQW1CTUVZMEFDZ2tRUmFpeDZHdk4KRUtZVURRLy9jSkNSRGFwTlhC UEd0anc5ZzdLaTgzV3FzcVNJRzk3WVpGMSs4dkYzRUtXYVEweWFVS3dQeUFoRgp5bmdScUlHem85 bmViZGs5SnU4ajhuRlBJQ1hLcTN6d21pSnpxZzQzbWdkRG9GamFWQ2dRTHYvVElQYmgvcG9pCitZ OUpNMFU0KzF0a0wyZVB5bHBHVGZnVFoyYVNOaDdEaVdSMmZzdklacFJvemVYK1hRQlhuWkpRQmJq Z0FDNUEKTmlmMnFGZ29oU1lyTVU3dGlpL080M2FIc0JTQ25qQmRxMXY4WCtPSTloTEFXbGNscncr c0pNVkFiRVZWRGZ0MQpVTSt2azlTSkFTMllHWjhoNnZ4SmtEUTJuNTg1MVAyMnZySWtSejFXVVZM L2VqbHd2QjVrazFQVDRueXg1M1dUCmFLZDdTd3ZYYmZiL252NUthTVN4NGtYbUFvcXVRemkvMW5l aTFVNjA0M1pMSDhyc2ZxdVhQaG8zSlVOWnoyOGgKMTRMajBuQndKMVp4ZUdoRC81L1hxTURXcC9B YnFYS2FJc25hRUtGWmRVWmZGUHdURXBnUmxudFRlVHMzVGl3cwpsOXh1b1YrUWliOHNsVzhaUlM3 Y3ZwRk85SG5tdDhSNk1RZ2s1bzB6RFAzc2RSYzN2OXJOOXdUNkNDSEFVRUhWCnRTWFBvYndSS29F QVpON0lRNENxdlhzQVdhMmVFTEVWNFhzMTgwNDVpQzVqNXoyU0NQNVFjVXJvMjBzaXhjME0KZVpG LzFBOFlvTTd1MVF4aHI5dzNwdHY5aWlDeXdrQldoWUxDQnFDNEJPVVlTREZtRHUvSUVyQTByYWlx TzJlOQpJZnNKV3poUWNGYW5BbjBjL05oekpmYWowdmhhcEN5d2NCZGtzdzg0Wm1ROWRYSzRFNEU9 Cj0zVCtwCi0tLS0tRU5EIFBHUCBTSUdOQVRVUkUtLS0tLQo= --==-=-=-- --=-=-= Content-Type: text/plain -------------------- End of forwarded message -------------------- --=-=-=-- From debbugs-submit-bounces@debbugs.gnu.org Mon Mar 15 09:43:25 2021 Received: (at control) by debbugs.gnu.org; 15 Mar 2021 13:43:26 +0000 Received: from localhost ([127.0.0.1]:35098 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lLnVF-0007Dv-JO for submit@debbugs.gnu.org; Mon, 15 Mar 2021 09:43:25 -0400 Received: from eggs.gnu.org ([209.51.188.92]:51442) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lLnVE-0007DW-IE for control@debbugs.gnu.org; Mon, 15 Mar 2021 09:43:24 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:40720) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lLnV9-0005Fw-BN for control@debbugs.gnu.org; Mon, 15 Mar 2021 09:43:19 -0400 Received: from [2a01:e0a:1d:7270:af76:b9b:ca24:c465] (port=45752 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1lLnV7-0002xe-Ln for control@debbugs.gnu.org; Mon, 15 Mar 2021 09:43:18 -0400 Date: Mon, 15 Mar 2021 14:43:16 +0100 Message-Id: <87lfaoh6rv.fsf@gnu.org> To: control@debbugs.gnu.org From: =?utf-8?Q?Ludovic_Court=C3=A8s?= Subject: control message for bug #47140 MIME-version: 1.0 Content-type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) tags 47140 + security quit From debbugs-submit-bounces@debbugs.gnu.org Wed Mar 24 00:06:33 2021 Received: (at control) by debbugs.gnu.org; 24 Mar 2021 04:06:33 +0000 Received: from localhost ([127.0.0.1]:33694 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lOumu-0005lF-Sj for submit@debbugs.gnu.org; Wed, 24 Mar 2021 00:06:33 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:54559) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lOumu-0005l0-0L for control@debbugs.gnu.org; Wed, 24 Mar 2021 00:06:32 -0400 Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id 00DAB5C00A6; Wed, 24 Mar 2021 00:06:27 -0400 (EDT) Received: from mailfrontend1 ([10.202.2.162]) by compute3.internal (MEProxy); Wed, 24 Mar 2021 00:06:27 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=date:from:to:message-id:mime-version:content-type; s=mesmtp; bh=cUzHWhlGR3wC+bHCNkVYv1pLnZKlAmeM2w5IIOGJO/Q=; b=hYoywwDcb45H +FnMoujfkLjlL2O862lHA5gu19YnLcGkyedy4g2r+8zkuxkV/0wCDl3ZYARsyaoQ gncttRvwfOB0FMOE2wn2BZGKsMDDR2NHFRvDuLmgLVE9W73e+f1eYRNLEHxLS4t2 q5jQWE6lWCJQQtJYSFhL1sFjiC5+NHU= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:message-id :mime-version:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=cUzHWhlGR3wC+bHCNkVYv1pLnZKlAmeM2w5IIOGJO /Q=; b=oBY0abGUV0V94XVxdUGYaDcNx44jbdINXGMiVoENwErL1yEyiGyJbPQDK KgbgNvQpHxuXtUvKddIOXBy+bW7zjdDZ6pCHF1UvgbbVyy7zARHXbgQJjqfnkoCp ZyzdR6eTojVI18aQnLJahMvztuvcnJvvpZ3JTPK5cXLzOGKf87Wa1h8WokpQfozP 1NG4H8Sc6HYjzRVTP+1Q0xA/mhIJKoETs8nKC9USahQ11JAQbaqB1Cpn6Y8s9xG7 U/fZIKBTlgGmSup44lnPYSzJwJd7bhKfPY19kMaWM7TtSioka1WU9C9wWYCuy6Z+ nmVqk+OOVCF+IbVpUS0FVk6RCNd4Q== X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrudegjedgieejucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucfgmhhpthihuchsuhgsjhgvtghtucdluddtmdenuc fjughrpeffhffvkfggtggusehttdertddttddvnecuhfhrohhmpefnvghoucfhrghmuhhl rghrihcuoehlvghosehfrghmuhhlrghrihdrnhgrmhgvqeenucggtffrrghtthgvrhhnpe fhjeeigfefvedvfeetheegledtkeevuddtgedtudeiteehteegvdefffduffefffenucfk phepuddttddruddurdduieelrdduudeknecuvehluhhsthgvrhfuihiivgeptdenucfrrg hrrghmpehmrghilhhfrhhomheplhgvohesfhgrmhhulhgrrhhirdhnrghmvg X-ME-Proxy: Received: from localhost (pool-100-11-169-118.phlapa.fios.verizon.net [100.11.169.118]) by mail.messagingengine.com (Postfix) with ESMTPA id C6F7224041D for ; Wed, 24 Mar 2021 00:06:26 -0400 (EDT) Date: Wed, 24 Mar 2021 00:06:25 -0400 From: Leo Famulari To: control@debbugs.gnu.org Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Spam-Score: 2.3 (++) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: block 47297 with 47140 block 47297 with 47141 block 47297 with 47142 block 47297 with 47143 block 47297 with 47144 Content analysis details: (2.3 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [66.111.4.25 listed in wl.mailspike.net] -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at https://www.dnswl.org/, low trust [66.111.4.25 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record -0.0 SPF_HELO_PASS SPF: HELO matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders 1.8 MISSING_SUBJECT Missing Subject: header 0.2 NO_SUBJECT Extra score for no subject 1.0 BODY_EMPTY No body text in message X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: block 47297 with 47140 block 47297 with 47141 block 47297 with 47142 block 47297 with 47143 block 47297 with 47144 Content analysis details: (1.3 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [66.111.4.25 listed in wl.mailspike.net] -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at https://www.dnswl.org/, low trust [66.111.4.25 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record -0.0 SPF_HELO_PASS SPF: HELO matches SPF record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders -1.0 MAILING_LIST_MULTI Multiple indicators imply a widely-seen list manager 1.8 MISSING_SUBJECT Missing Subject: header 0.2 NO_SUBJECT Extra score for no subject 1.0 BODY_EMPTY No body text in message block 47297 with 47140 block 47297 with 47141 block 47297 with 47142 block 47297 with 47143 block 47297 with 47144 From debbugs-submit-bounces@debbugs.gnu.org Mon Apr 05 16:51:20 2021 Received: (at 47140) by debbugs.gnu.org; 5 Apr 2021 20:51:20 +0000 Received: from localhost ([127.0.0.1]:38730 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lTWBs-0004y7-Bg for submit@debbugs.gnu.org; Mon, 05 Apr 2021 16:51:20 -0400 Received: from mail.zaclys.net ([178.33.93.72]:43249) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lTWBq-0004xr-Kz for 47140@debbugs.gnu.org; Mon, 05 Apr 2021 16:51:19 -0400 Received: from [192.168.1.115] (lsl43-1_migr-78-195-19-20.fbx.proxad.net [78.195.19.20] (may be forged)) (authenticated bits=0) by mail.zaclys.net (8.14.7/8.14.7) with ESMTP id 135KpB0U057058 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <47140@debbugs.gnu.org>; Mon, 5 Apr 2021 22:51:12 +0200 DMARC-Filter: OpenDMARC Filter v1.3.2 mail.zaclys.net 135KpB0U057058 Authentication-Results: mail.zaclys.net; dmarc=fail (p=reject dis=none) header.from=zaclys.net Authentication-Results: mail.zaclys.net; spf=fail smtp.mailfrom=lle-bout@zaclys.net DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zaclys.net; s=default; t=1617655872; bh=cnMXBgYbWOadBuZgboS8ogPhgKoSZdygYcKJrdDoPnw=; h=Subject:From:To:Date:From; b=dhsyN6ByR5vpcCyACtg33fo+nQT84ut1gtE+3JXGLgBV/wGEOAC0sc6EbXl5Gpo3A 3Z9xS+LdWXaNJkj3FvU4wJu6xLttLNn3Jon2hiVBH7gpuytUJJPILXyhsLv4WfKLzu d2ja+zz30QgvxIMPVieUa6o7C6OF+VI27kVXn564= Message-ID: Subject: libupnp package vulnerable to CVE-2021-28302 From: =?ISO-8859-1?Q?L=E9o?= Le Bouter To: 47140@debbugs.gnu.org Date: Mon, 05 Apr 2021 22:50:56 +0200 Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-Ro2zO5DIVwG1xSUK4+BF" User-Agent: Evolution 3.34.2 MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 47140 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-Ro2zO5DIVwG1xSUK4+BF Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Upstream created and merged a probable patch:=20 https://github.com/pupnp/pupnp/pull/306 Reporter still needs to confirm if it fixes the issue. --=-Ro2zO5DIVwG1xSUK4+BF Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEFIvLi9gL+xax3g6RRaix6GvNEKYFAmBreDAACgkQRaix6GvN EKbPTA/+MBbgjAjTCTeZ54pKRRUQdP8Pcb2IVreT0GmIpsiTGJeH8+4uFegkj/jJ AA5vCyPuzEw+3P+4O9QKFbVvJq0znioA5fDHp9OvKdvTukRAu4rdaV/8EnRQnnVH o/E23QgoUXbnCftpKzzI2NAgQWgJokfOeoaQho/b/kPlf3s9Mizr0GgX5kkXjHVC ycw4IvMlabZor4ECujDHRhToNogkp2dO6929wf5/efl0pC8a1Bv5fbUDWvsSLyVX sPrOTsEGo/D0yK6rucVG4D59B/YgGsljloB35upSatM0hmOFX6ynfHlj91kyf5qF ks+9VeCIpm2fPyth+wTN7hu87MyNwMi6ZjjTmZ7G9NI+EyOQ3F+kPZREHZNFHhC7 5sVG8L0LFleCqrJWQgMXMZU6bF+guYrV01CGBczzvHwz4bxgT+zA2k/wW6/QTYlG IjvnWwOe+pYuBVX1/cx77iguvU4FNRG+tXC8rqhYsLjF5fpuDbDUQv9DCfDoYmkK SStYWyAH/8eLlKZprMbJUsa494MedFWyqdRCuiIxMykUVBz30rfHlcZXp1aXDz0k 9gUg+3GZQbcc4FKQG2znw5z4o4AHnqsfeffljph6Oqx9Y9/0iV1H080J5uE90xhl fDlsu/rG3Aw0NzIlka8eBIKr9fSdkEKwti3FDu6/Hd+ihStWL/0= =jvyO -----END PGP SIGNATURE----- --=-Ro2zO5DIVwG1xSUK4+BF-- From debbugs-submit-bounces@debbugs.gnu.org Thu Apr 08 21:16:27 2021 Received: (at 47140-done) by debbugs.gnu.org; 9 Apr 2021 01:16:27 +0000 Received: from localhost ([127.0.0.1]:48618 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lUfl5-0008OT-A7 for submit@debbugs.gnu.org; Thu, 08 Apr 2021 21:16:27 -0400 Received: from mail.zaclys.net ([178.33.93.72]:35047) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lUfl2-0008OF-H9 for 47140-done@debbugs.gnu.org; Thu, 08 Apr 2021 21:16:25 -0400 Received: from [192.168.1.115] (lsl43-1_migr-78-195-19-20.fbx.proxad.net [78.195.19.20] (may be forged)) (authenticated bits=0) by mail.zaclys.net (8.14.7/8.14.7) with ESMTP id 1391GHLY049175 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <47140-done@debbugs.gnu.org>; Fri, 9 Apr 2021 03:16:17 +0200 DMARC-Filter: OpenDMARC Filter v1.3.2 mail.zaclys.net 1391GHLY049175 Authentication-Results: mail.zaclys.net; dmarc=fail (p=reject dis=none) header.from=zaclys.net Authentication-Results: mail.zaclys.net; spf=fail smtp.mailfrom=lle-bout@zaclys.net DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zaclys.net; s=default; t=1617930977; bh=nIVuMUXjE8t5bcpeV6/1UkCFDwhK0j/G1vti+CuNhf0=; h=Subject:From:To:Date:From; b=TlJn/LalcL0ECJlZj12TwSlHa+wn9f1kpLYsyHGOjh6ifarmIYY2FMCgYCueCQKVD ocfjiq9WEpBEe24AJi8bBg8ewL8WeqfoXIBoNXFZvPRxitzUUJDiYyaWejUX4Wa5fz j0s/q6BrAbX2pzCGpVixFlpMh4jIDlREiuTGJR7k= Message-ID: <5d2864e3ee90af06e3abc6e7899fa80de0b72ded.camel@zaclys.net> Subject: libupnp package vulnerable to CVE-2021-28302 From: =?ISO-8859-1?Q?L=E9o?= Le Bouter To: 47140-done@debbugs.gnu.org Date: Fri, 09 Apr 2021 03:16:11 +0200 Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-JANXwFojr6tfQLWLDW6q" User-Agent: Evolution 3.34.2 MIME-Version: 1.0 X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 47140-done X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-JANXwFojr6tfQLWLDW6q Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Fixed by 2b605ef3b145ec136530f08ee7aa27382aa64b46 --=-JANXwFojr6tfQLWLDW6q Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEFIvLi9gL+xax3g6RRaix6GvNEKYFAmBvqtsACgkQRaix6GvN EKa1Cw//d68L/ApbojqQHLvSDo5FrQPnkmFY9LnWB07qx1j68sJwUW9OYYtDcA4w h1wFdm0/8u/Lj4gifo+aW0Cxm27BzCpf+QRRp2XSRkKQh8nWR8l/LUzVN65obSA6 iJlaV7o5w9f12GI44UxyT8pYTq5qJdaSowmsdwpPvQ/9iKj0Kx2PqT20Nr6XRdsP sy/Y3y/c31SArwA8B9UDbMi3Ye/vgOSMv32aZOsRixAImkxPqzYq/PaKq463Jg5V ErNjDM0fsQUFb8QzHQr9B9LXpUzWaHAC31/fFcaKidThPD8s8SUUY8FtZ5Jc6eTW sDxXLZTcrMAno0Lh91K+H9bIZ39VZyZWJ88gzvo4JaydbCuaq9xms1CkwRcY0QSb Jq2Lcj95cdqXeiUfEYFDBGcCHV/wVwfTAxHkblqbjbDS1IHKZYR4B/5PYYh6prTn srBzPs1fn+xqDj2EzCs2JIMe82aZRQgUitCq64oMH9UPcLM7wS9bJ1JFUMyMU5il FP0evjwoQo4jJ0Tbj3fYmUn7C/VCm0Xv9xumlcgbxNL7fJZNsAmZdSaFA40Hfhqa pDBRz0vpFqTurGv/AbBrRM0asHzp2mRPhh1Z2GIZ9jL5EtgDTfp0EAMDZsgbeUN1 dp6mURYr43y6gD4JbokNBbfYEoaacREZeXKqCoKXHScx3U3EYI4= =epMm -----END PGP SIGNATURE----- --=-JANXwFojr6tfQLWLDW6q-- From unknown Sat Jun 21 10:22:22 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Fri, 07 May 2021 11:24:05 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator