07-01-2020, 07:50 AM
Just had noticfiaction that the issue I raised with upmpdcli ver 1.4.12 has been fixed (as per this link:7ea91f5d )
Thank you for your donation!
Upcoming moOde 6.6.0 feature release
|
07-01-2020, 07:50 AM
Just had noticfiaction that the issue I raised with upmpdcli ver 1.4.12 has been fixed (as per this link:7ea91f5d )
07-01-2020, 04:25 PM
Success with the first moOde 6.6.0 test build using RaspiOS 10.4 and kernel 5.4.49 :-)
This includes the latest 1.4.12-7ea91f5d upmpdcli with the volume fix. Code: ########################################################
07-01-2020, 04:30 PM
SWEET!
07-02-2020, 11:40 AM
Looking forward to 6.6.0! May thanks for incorprating that fix in upmpdcli ver 1.4.12 Tim.
I've just become aware of what seems to be a pretty nasty upnp vulnerability (CVE-2020-12695, aka 'CallStranger') which Jean-Francois has addressed in the latest versions of libnpupnp and libupnpp (4.0.7 and 0.19.2). I'm not sure if you've already picked up on this - apologises if this means yet more work
07-02-2020, 11:52 AM
Post a link to the issue and I'll have a look.
07-02-2020, 11:55 AM
UpnP is a dumpster fire from a security standpoint. This vulnerability is in the protocol itself so every implementation is suspect. Router firewalls remain our best line of defense.
Regards, Kent
07-02-2020, 12:09 PM
moOde itself is not a secure system and should never have a direct connection to the Public Internet. Thats just inviting trouble :-0
OTOH if a link explaining a security vulnerability is posted I'll check it out.
07-02-2020, 12:27 PM
Agreed. I just wanted folks to know Jean-Francois didn't somehow create this problem.
My biggest concern is my grandkids' Xboxes and other gaming consoles running on the same LANs as their parents' laptops used for work-from-home, banking apps, etc. I'm a little suspect too of our Verizon FiOS settop box and its communication through the Verizon FiOS modem/router. Regards, Kent |
« Next Oldest | Next Newest »
|