Important: gupnp security update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:2363', 'synopsis': 'Important: gupnp security update', 'severity': 'Important', 'topic': 'An update for gupnp is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'GUPnP is an object-oriented open source framework for creating UPnP devices and control points, written in C using GObject and libsoup. The GUPnP API is intended to be easy to use, efficient and flexible.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1964091'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-33516.json:::CVE-2021-33516'], 'references': [], 'publishedAt': '2021-07-22T03:27:11.111164Z', 'rpms': ['gupnp-1.0.6-2.el8_4.aarch64.rpm', 'gupnp-1.0.6-2.el8_4.i686.rpm', 'gupnp-1.0.6-2.el8_4.src.rpm', 'gupnp-1.0.6-2.el8_4.x86_64.rpm', 'gupnp-debuginfo-1.0.6-2.el8_4.aarch64.rpm', 'gupnp-debuginfo-1.0.6-2.el8_4.i686.rpm', 'gupnp-debuginfo-1.0.6-2.el8_4.x86_64.rpm', 'gupnp-debugsource-1.0.6-2.el8_4.aarch64.rpm', 'gupnp-debugsource-1.0.6-2.el8_4.i686.rpm', 'gupnp-debugsource-1.0.6-2.el8_4.x86_64.rpm', 'gupnp-devel-1.0.6-2.el8_4.aarch64.rpm', 'gupnp-devel-1.0.6-2.el8_4.i686.rpm', 'gupnp-devel-1.0.6-2.el8_4.x86_64.rpm', 'gupnp-docs-1.0.6-2.el8_4.noarch.rpm']}\. A vital security patch for gupnp has just been released for Rocky Linux 8, tackling significant vulnerabilities and threats.. GUPnP Security Fix, Rocky Linux 8, Important Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gupnp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:2153-1 Rating: important References: #1186590 Cross-References: CVE-2021-33516 CVSS scores: CVE-2021-33516 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVE-2021-33516 (SUSE): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gupnp fixes the following issues: - CVE-2021-33516: Fixed a DNS rebinding, which could trick the browser into triggering actions against local UPnP services (bsc#1186590). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-2153=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): gupnp-debugsource-1.2.2-3.3.1 libgupnp-1_2-0-1.2.2-3.3.1 libgupnp-1_2-0-debuginfo-1.2.2-3.3.1 libgupnp-devel-1.2.2-3.3.1 typelib-1_0-GUPnP-1_0-1.2.2-3.3.1 - openSUSE Leap 15.3 (x86_64): libgupnp-1_2-0-32bit-1.2.2-3.3.1 libgupnp-1_2-0-32bit-debuginfo-1.2.2-3.3.1 References: https://www.suse.com/security/cve/CVE-2021-33516.html https://bugzilla.suse.com/1186590 . Addresses a significant DNS rebinding vulnerability in gupnp with a vital patch for openSUSE. Apply this now to protect your system.. openSUSE,gupnp,security update,DNS rebinding,important fixes. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gupnp ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0917-1 Rating: important References: #1186590 Cross-References: CVE-2021-33516 CVSS scores: CVE-2021-33516 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVE-2021-33516 (SUSE): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gupnp fixes the following issues: - CVE-2021-33516: Fixed a DNS rebinding, which could trick the browser into triggering actions against local UPnP services (bsc#1186590). This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-917=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): gupnp-debugsource-1.2.2-lp152.2.3.1 libgupnp-1_2-0-1.2.2-lp152.2.3.1 libgupnp-1_2-0-debuginfo-1.2.2-lp152.2.3.1 libgupnp-devel-1.2.2-lp152.2.3.1 typelib-1_0-GUPnP-1_0-1.2.2-lp152.2.3.1 - openSUSE Leap 15.2 (x86_64): libgupnp-1_2-0-32bit-1.2.2-lp152.2.3.1 libgupnp-1_2-0-32bit-debuginfo-1.2.2-lp152.2.3.1 References: https://www.suse.com/security/cve/CVE-2021-33516.html https://bugzilla.suse.com/1186590 . A crucial enhancement for Fedora addresses a vulnerability in the avahi service related to DNS rebinding, bolstering overall system protection.. openSUSE Security,gupnp Update,DNS Rebinding Fix,ImportantPatch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for gupnp ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2153-1 Rating: important References: #1186590 Cross-References: CVE-2021-33516 CVSS scores: CVE-2021-33516 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVE-2021-33516 (SUSE): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP3 SUSE Linux Enterprise Workstation Extension 15-SP2 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gupnp fixes the following issues: - CVE-2021-33516: Fixed a DNS rebinding, which could trick the browser into triggering actions against local UPnP services (bsc#1186590). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-WE-15-SP3-2021-2153=1 - SUSE Linux Enterprise Workstation Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-WE-15-SP2-2021-2153=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2021-2153=1 - SUSE Linux Enterprise Module for PackagehubSubpackages 15-SP2: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP2-2021-2153=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP3-2021-2153=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2021-2153=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP3 (x86_64): gupnp-debugsource-1.2.2-3.3.1 typelib-1_0-GUPnP-1_0-1.2.2-3.3.1 - SUSE Linux Enterprise Workstation Extension 15-SP2 (x86_64): gupnp-debugsource-1.2.2-3.3.1 typelib-1_0-GUPnP-1_0-1.2.2-3.3.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (aarch64 ppc64le s390x x86_64): gupnp-debugsource-1.2.2-3.3.1 libgupnp-devel-1.2.2-3.3.1 typelib-1_0-GUPnP-1_0-1.2.2-3.3.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 (aarch64 ppc64le s390x x86_64): gupnp-debugsource-1.2.2-3.3.1 libgupnp-devel-1.2.2-3.3.1 typelib-1_0-GUPnP-1_0-1.2.2-3.3.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (aarch64 ppc64le s390x x86_64): gupnp-debugsource-1.2.2-3.3.1 libgupnp-1_2-0-1.2.2-3.3.1 libgupnp-1_2-0-debuginfo-1.2.2-3.3.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (aarch64 ppc64le s390x x86_64): gupnp-debugsource-1.2.2-3.3.1 libgupnp-1_2-0-1.2.2-3.3.1 libgupnp-1_2-0-debuginfo-1.2.2-3.3.1 References: https://www.suse.com/security/cve/CVE-2021-33516.html https://bugzilla.suse.com/1186590 . SUSE has released a security update addressing a severe DNS rebinding issue in gupnp. It is advised to apply the patch without delay.. SUSE gupnp update,DNS rebinding threat,security update. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for gupnp ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2080-1 Rating: important References: #1186590 Cross-References: CVE-2021-33516 CVSS scores: CVE-2021-33516 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVE-2021-33516 (SUSE): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gupnp fixes the following issues: - CVE-2021-33516: Fixed a DNS rebinding, which could trick the browser into triggering actions against local UPnP services (bsc#1186590). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2021-2080=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-2080=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): gupnp-debugsource-0.20.18-8.3.1 libgupnp-1_0-4-0.20.18-8.3.1 libgupnp-1_0-4-debuginfo-0.20.18-8.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): gupnp-debugsource-0.20.18-8.3.1 libgupnp-1_0-4-0.20.18-8.3.1 libgupnp-1_0-4-debuginfo-0.20.18-8.3.1 libgupnp-devel-0.20.18-8.3.1 typelib-1_0-GUPnP-1_0-0.20.18-8.3.1 References: https://www.suse.com/security/cve/CVE-2021-33516.html https://bugzilla.suse.com/1186590 . A recent SUSE Security Update resolves a significant DNS rebinding vulnerability in gupnp. This advisory emphasizes the importance of maintaining system integrity.. SUSE Updates, gupnp Security, DNS Rebinding Fix, Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Upstream details at : https://access.redhat.com/errata/RHSA-2018:3140. CentOS Errata and Security Advisory 2018:3140 Moderate Upstream details at : https://access.redhat.com/errata/RHSA-2018:3140 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 86993bde440204eca01ab08264c50ea2e67b216b8b0460a9abd7ed1e48864926 gupnp-1.0.2-6.el7_9.i686.rpm d5da28b2cc382844aa578c0eb19c23535d011518b699a177d00f377554f5c80a gupnp-1.0.2-6.el7_9.x86_64.rpm 160346449f601718afb8de2d7f7e0aeb2ac8a5f4e2163d2f74d1b98233db4002 gupnp-devel-1.0.2-6.el7_9.i686.rpm ecb7f8d19fb659a35a4a25d22a891cfd89fd55cc12d791df222c33eba1c9dbdb gupnp-devel-1.0.2-6.el7_9.x86_64.rpm bc77febf9b5e706cc4d68361638309818761fa19dfe82ca91496f40a23d81bac gupnp-docs-1.0.2-6.el7_9.noarch.rpm Source: b1fa366fa43e6586685c2cadbc18e54542f7ea4cd6087ee07e615c49b9b5d15b gupnp-1.0.2-6.el7_9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
An update for gupnp is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: gupnp security update Advisory ID: RHSA-2021:2459-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2459 Issue date: 2021-06-16 CVE Names: CVE-2021-33516 ==================================================================== 1. Summary: An update for gupnp is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v. 8.1) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream EUS (v. 8.1) - aarch64, ppc64le, s390x, x86_64 3. Description: GUPnP is an object-oriented open source framework for creating UPnP devices and control points, written in C using GObject and libsoup. The GUPnP API is intended to be easy to use, efficient and flexible. Security Fix(es): * gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services (CVE-2021-33516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1964091 - CVE-2021-33516 gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services 6. Package List: Red Hat Enterprise Linux AppStream EUS (v. 8.1): Source: gupnp-1.0.3-3.el8_1.src.rpm aarch64: gupnp-1.0.3-3.el8_1.aarch64.rpm gupnp-debuginfo-1.0.3-3.el8_1.aarch64.rpm gupnp-debugsource-1.0.3-3.el8_1.aarch64.rpm ppc64le: gupnp-1.0.3-3.el8_1.ppc64le.rpm gupnp-debuginfo-1.0.3-3.el8_1.ppc64le.rpm gupnp-debugsource-1.0.3-3.el8_1.ppc64le.rpm s390x: gupnp-1.0.3-3.el8_1.s390x.rpm gupnp-debuginfo-1.0.3-3.el8_1.s390x.rpm gupnp-debugsource-1.0.3-3.el8_1.s390x.rpm x86_64: gupnp-1.0.3-3.el8_1.i686.rpm gupnp-1.0.3-3.el8_1.x86_64.rpm gupnp-debuginfo-1.0.3-3.el8_1.i686.rpm gupnp-debuginfo-1.0.3-3.el8_1.x86_64.rpm gupnp-debugsource-1.0.3-3.el8_1.i686.rpm gupnp-debugsource-1.0.3-3.el8_1.x86_64.rpm Red Hat CodeReady Linux Builder EUS (v. 8.1): aarch64: gupnp-debuginfo-1.0.3-3.el8_1.aarch64.rpm gupnp-debugsource-1.0.3-3.el8_1.aarch64.rpm gupnp-devel-1.0.3-3.el8_1.aarch64.rpm ppc64le: gupnp-debuginfo-1.0.3-3.el8_1.ppc64le.rpm gupnp-debugsource-1.0.3-3.el8_1.ppc64le.rpm gupnp-devel-1.0.3-3.el8_1.ppc64le.rpm s390x: gupnp-debuginfo-1.0.3-3.el8_1.s390x.rpm gupnp-debugsource-1.0.3-3.el8_1.s390x.rpm gupnp-devel-1.0.3-3.el8_1.s390x.rpm x86_64: gupnp-debuginfo-1.0.3-3.el8_1.i686.rpm gupnp-debuginfo-1.0.3-3.el8_1.x86_64.rpm gupnp-debugsource-1.0.3-3.el8_1.i686.rpm gupnp-debugsource-1.0.3-3.el8_1.x86_64.rpm gupnp-devel-1.0.3-3.el8_1.i686.rpm gupnp-devel-1.0.3-3.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-33516 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYMn5Z9zjgjWX9erEAQh48w//Sln93WgrCjoA3sf08Z2mRTFa3ohz00/g nAGB/jpqVOXUeccfGSlA9yeUKlP7lmy+YZyp0sKNwkWcGyLZyrHE9T7boogSoP1v cdQeQoYa/8g/ky8TacNJlnm4EWkAuh0en60b4K0Yb5dzL7A/QgT9r5R99E02gts+ DLsIz53a4ytej5m/XLxhb6g8PpQGCEmrXDs2+XN+vm3xqrRyg200HIc7c0zqaHop Jt3lfCoqt5bfyaFhG9X7yAhHyFqH7FQiVC6/0vhiDdJX0PgGF/0PNmrafb7e/GTH qWLYcLzzY0ajgjByeQSewm6jhVQiAvq4fxZLCuw1ELKUNuV9r21leihm2YskJae2 mYjSwCTjmbRaqcmav9Na3GLG24d8sClFdIFqbbEVsWv+q/Bn5PC0I/jCltXgtGZ8 kYEe8eoGCpmcZNX0QzEuz3BtrcXMjJqTMBRkGUNG8IIvS54FadGLW/QkZuxOp5Rz 4eCffj9kq6xG9vjj4BBG5dKNpTE/JiQeX92sfawJLinWZX7U2eGdhAHobn9fWzc6 yXT8eWf1rfc7bLYcBA9HLwDXo7/r3UOQGHAvyAT+NDmE/H8grTN9nXJX7Zs0Zr9K QCAB2CWawwcGtAyejDTFY15P+6W3RUIJ7RvtLzhH8YTXUbb4buP0cv4NX4kj/qCG djkiq+VZKrI=mXuH -----END PGP SIGNATURE----- -- RHSA-announce mailing list
gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services (CVE-2021-33516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE --- SL7 x86_64 gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_ [More...]. Synopsis: Important: gupnp security update Advisory ID: SLSA-2021:2417-1 Issue Date: 2021-06-15 CVE Numbers: CVE-2021-33516 -- Security Fix(es): * gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services (CVE-2021-33516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE --- SL7 x86_64 gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_9.i686.rpm gupnp-debuginfo-1.0.2-6.el7_9.x86_64.rpm gupnp-devel-1.0.2-6.el7_9.i686.rpm gupnp-devel-1.0.2-6.el7_9.x86_64.rpm noarch gupnp-docs-1.0.2-6.el7_9.noarch.rpm -- - Scientific Linux Development Team . A critical GUPnP security flaw exposes SL7 x86_64 systems to DNS rebinding attacks. Immediate patching is essential to protect sensitive information and network integrity. Gupnp Security Advisory, Important Update Gupnp, DNS Rebinding SL7, Browser Exploit Presentation, Scientific Linux Security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.