MGASA-2014-0435
Dashboard / Vulnerabilities / MGASA-2014-0435
MGASA-2014-0435
Summary: Updated MythTV packages to harden against SSDP reflection attacks
Details: Updated MythTV packages to harden against SSDP reflection attacks MythTV's UPNP component was suseptable to SSDP reflection attacks and has been hardened to disallow SSDP device discovery from non-local addresses as mitigation. Additionally, a popular schedules retrieval service, Schedules Direct, will deprecate the old URL used by MythTV to retrieve metadata on 1st November 2015. This build of MythTV also updates the URL for this this service for continued operation going forward.
References: https://advisories.mageia.org/MGASA-2014-0435.html, https://bugs.mageia.org/show_bug.cgi?id=14347, https://www.prolexic.com/knowledge-center-ddos-threat-advisory-ssdp-reflection-ddos-attacks.html, https://www.prolexic.com/kcresources/prolexic-threat-advisories/prolexic-threat-advisory-ssdp-reflection-ddos-attacks/ssdp-reflection-attacks-cybersecurity-locked.html
Affected packages
Package
Name: mythtv
Purl: pkg:rpm/mageia/mythtv?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
