Bug#703281:

2013-04-29 Thread Jens Georg
> additional facts: activating and deactivating the checkbox in rygel > preferences does not have any effect if not done a full halt and start > with each change of the checkbox. restarting rygel preferences does not > take effect. This is intentional; older versions of Rygel can't react on config

Bug#703281: rygel security issue

2013-04-29 Thread n8fer
Ok I got a full analyse of the behaviour: (Tested with debian wheezy rc2. each test was performed on a fresh installation) how to activate rygel after triggering the bug: starting and closing rygel for the first time (without changing the checkbox) this triggers the bug. full start and stop

Bug#703281: rygel security issue

2013-04-28 Thread n8fer
> Can partially confirm, but all that this does is setting the checkmark > in the UI. While this is confusing, it doesn't actually launch Rygel or > create the symlink necessary to autostart Rygel; no media is shared by > accident just by launching rygel-preferences twice. I have spend some time

Bug#703281:

2013-04-22 Thread Jens Georg
Can partially confirm, but all that this does is setting the checkmark in the UI. While this is confusing, it doesn't actually launch Rygel or create the symlink necessary to autostart Rygel; no media is shared by accident just by launching rygel-preferences twice. -- To UNSUBSCRIBE, email to de

Bug#703281: rygel security issue

2013-04-21 Thread Andreas Henriksson
Hello Michael Karcher! On Sun, Apr 21, 2013 at 02:53:27PM +0200, Michael Karcher wrote: > This behaviour is caused by the global (system wide) configuration file > /etc/rygel.conf containing "upnp-enabled=true". [...] > A short-term fix would be to ship with "upnp-enabled=false" in the global > co

Bug#703281: rygel security issue

2013-04-21 Thread Michael Karcher
Package: rygel Version: 0.14.3-2 Followup-For: Bug #703281 This behaviour is caused by the global (system wide) configuration file /etc/rygel.conf containing "upnp-enabled=true". That file is used as template for the local (user specific) configuration file, which is written when you

Bug#703281: rygel security issue

2013-04-20 Thread John Paul Adrian Glaubitz
Since the problem is reproducible only when rygel-preferences is run for the first and second time consecutively (no ~/.config/rygel.conf initially exists), it must be related to the fact that rygel-preferences cannot find an existing configuration file and hence a default setting for the shari

Bug#703281: rygel security issue

2013-03-18 Thread mike . a . oliver
On Sunday, March 17, 2013 7:20:01 PM UTC-4, deb...@lavabit.com wrote: > Package: rygel > > Version: 0.14.3-2 > > Severity: important > > > > > > Dear Maintainer, > > > > > > The current version of rygel which is part of Debian Wheezy contains a > > possibly security issue: > > > > W

Bug#703281: rygel security issue

2013-03-18 Thread debmail
Package: rygel Version: 0.14.3-2 Severity: important > On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: > [...] >> When starting rygel preferences a second time (without having changed >> the >> preferences) the sharing option is activated. > > Unreproducible. The bug is on

Bug#703281: rygel security issue

2013-03-18 Thread debmail
> On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: > [...] >> When starting rygel preferences a second time (without having changed >> the >> preferences) the sharing option is activated. > > Unreproducible. The bug is only reproducible when using rygel the first time. When o

Bug#703281: rygel sharing bug

2013-03-18 Thread root
Package: rygel Version: 0.14.3-2 Followup-For: Bug #703281 Dear Maintainer, These are the reporttool results for the "rygel security issue" report -- System Information: Debian Release: 7.0 APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) K

Bug#703281: rygel security issue

2013-03-17 Thread Andreas Henriksson
On Sun, Mar 17, 2013 at 07:12:59PM -0400, debm...@lavabit.com wrote: [...] > When starting rygel preferences a second time (without having changed the > preferences) the sharing option is activated. Unreproducible. > > Therefore everyone starting rygel preferences for once, activates the uPnP >

Bug#703281: rygel security issue

2013-03-17 Thread debmail
Package: rygel Version: 0.14.3-2 Severity: important Dear Maintainer, The current version of rygel which is part of Debian Wheezy contains a possibly security issue: When starting rygel preferences a second time (without having changed the preferences) the sharing option is activated. Therefo