Package: rygel
Version: 0.14.3-2
Severity: critical
Justification: causes serious data loss

Dear Maintainer,

The current Version of rygel in Debian Wheezy contains a bug, 
which may lead to data loss as well as security issues.

When stating rygel preferences for the first time, 
the sharing option is automaticly activated 
(without showing an activated checkbox)

This leads to unintended exposure of personal files as well as
a additional service offered on the network which may lead to additional 
security problems.

Considering the severity for users of mobil devices, this should be fixed
before the final release.


-- System Information:
Debian Release: 7.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 3.2.0-4-686-pae (SMP w/1 CPU core)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages rygel depends on:
ii  libc6                            2.13-38
ii  libgee2                          0.6.4-2
ii  libglib2.0-0                     2.33.12+really2.32.4-5
ii  libgssdp-1.0-3                   0.12.2.1-2
ii  libgstreamer-plugins-base0.10-0  0.10.36-1.1
ii  libgstreamer0.10-0               0.10.36-1.1
ii  libgupnp-1.0-4                   0.18.4-1
ii  libgupnp-av-1.0-2                0.10.3-1
ii  libgupnp-dlna-1.0-2              0.6.6-1
ii  libsoup2.4-1                     2.38.1-2
ii  libsqlite3-0                     3.7.13-1
ii  libunistring0                    0.9.3-5
ii  libuuid1                         2.20.1-5.3
ii  libxml2                          2.8.0+dfsg1-7+nmu1

Versions of packages rygel recommends:
ii  gstreamer0.10-ffmpeg        0.10.13-5
ii  gstreamer0.10-plugins-base  0.10.36-1.1
ii  gstreamer0.10-plugins-ugly  0.10.19-2+b2

Versions of packages rygel suggests:
pn  rygel-mediathek    <none>
ii  rygel-playbin      0.14.3-2
ii  rygel-preferences  0.14.3-2
ii  rygel-tracker      0.14.3-2
pn  tumbler            <none>

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to